blob: bfac7e987ee85056a3ed2595009443af1015ffea [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010084
Harald Welte4263c522018-12-06 11:56:27 +010085/* Needed for SGsAP SMS */
86import from MobileL3_SMS_Types all;
87
Harald Weltea4ca4462018-02-09 00:17:14 +010088type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010089 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010090
Harald Welte6811d102019-04-14 22:23:14 +020091 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010092
Harald Weltea49e36e2018-01-21 19:29:33 +010093 /* no 'adapter_CT' for MNCC or GSUP */
94 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010095 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010096 var GSUP_Emulation_CT vc_GSUP;
97 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020098 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010099 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100100
101 /* only to get events from IPA underneath GSUP */
102 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100103 /* VTY to MSC */
104 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100105
106 /* A port to directly send BSSAP messages. This port is used for
107 * tests that require low level access to sen arbitrary BSSAP
108 * messages. Run f_init_bssap_direct() to connect and initialize */
109 port BSSAP_CODEC_PT BSSAP_DIRECT;
110
111 /* When BSSAP messages are directly sent, then the connection
112 * handler is not active, which means that also no guard timer is
113 * set up. The following timer will serve as a replacement */
114 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100115
116 /* Configure T(tias) over VTY, seconds */
117 var integer g_msc_sccp_timer_ias := 7 * 60;
118 /* Configure T(tiar) over VTY, seconds */
119 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100120}
121
122modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100123 /* remote parameters of IUT */
124 charstring mp_msc_ip := "127.0.0.1";
125 integer mp_msc_ctrl_port := 4255;
126 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100127
Harald Weltea49e36e2018-01-21 19:29:33 +0100128 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100129 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 charstring mp_hlr_ip := "127.0.0.1";
131 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100132 charstring mp_mgw_ip := "127.0.0.1";
133 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100134
Harald Weltea49e36e2018-01-21 19:29:33 +0100135 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100136
Harald Weltef640a012018-04-14 17:49:21 +0200137 integer mp_msc_smpp_port := 2775;
138 charstring mp_smpp_system_id := "msc_tester";
139 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100140 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
141 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200142
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200143 /* Whether to enable osmux tests. Can be dropped completely and enable
144 unconditionally once new version of osmo-msc is released (current
145 version: 1.3.1) */
146 boolean mp_enable_osmux_test := true;
147
Harald Welte6811d102019-04-14 22:23:14 +0200148 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200149 {
150 sccp_service_type := "mtp3_itu",
151 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
152 own_pc := 185,
153 own_ssn := 254,
154 peer_pc := 187,
155 peer_ssn := 254,
156 sio := '83'O,
157 rctx := 0
158 },
159 {
160 sccp_service_type := "mtp3_itu",
161 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
162 own_pc := 186,
163 own_ssn := 254,
164 peer_pc := 187,
165 peer_ssn := 254,
166 sio := '83'O,
167 rctx := 1
168 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100169 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100170}
171
Philipp Maier328d1662018-03-07 10:40:27 +0100172/* altstep for the global guard timer (only used when BSSAP_DIRECT
173 * is used for communication */
174private altstep as_Tguard_direct() runs on MTC_CT {
175 [] Tguard_direct.timeout {
176 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200177 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100178 }
179}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100180
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100181private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
182 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
183 if (respond) {
184 var BIT1 tid_remote := '1'B;
185 if (cpars.mo_call) {
186 tid_remote := '0'B;
187 }
188 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
189 }
190 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100191}
192
Harald Weltef640a012018-04-14 17:49:21 +0200193function f_init_smpp(charstring id) runs on MTC_CT {
194 id := id & "-SMPP";
195 var EsmePars pars := {
196 mode := MODE_TRANSCEIVER,
197 bind := {
198 system_id := mp_smpp_system_id,
199 password := mp_smpp_password,
200 system_type := "MSC_Tests",
201 interface_version := hex2int('34'H),
202 addr_ton := unknown,
203 addr_npi := unknown,
204 address_range := ""
205 },
206 esme_role := true
207 }
208
209 vc_SMPP := SMPP_Emulation_CT.create(id);
210 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
211 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
212}
213
214
Harald Weltea49e36e2018-01-21 19:29:33 +0100215function f_init_mncc(charstring id) runs on MTC_CT {
216 id := id & "-MNCC";
217 var MnccOps ops := {
218 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
219 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
220 }
221
222 vc_MNCC := MNCC_Emulation_CT.create(id);
223 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
224 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100225}
226
Harald Welte4aa970c2018-01-26 10:38:09 +0100227function f_init_mgcp(charstring id) runs on MTC_CT {
228 id := id & "-MGCP";
229 var MGCPOps ops := {
230 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
231 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
232 }
233 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100234 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100235 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100236 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200237 mgw_udp_port := mp_mgw_port,
238 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100239 }
240
241 vc_MGCP := MGCP_Emulation_CT.create(id);
242 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
243 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
244}
245
Philipp Maierc09a1312019-04-09 16:05:26 +0200246function ForwardUnitdataCallback(PDU_SGsAP msg)
247runs on SGsAP_Emulation_CT return template PDU_SGsAP {
248 SGsAP_CLIENT.send(msg);
249 return omit;
250}
251
Harald Welte4263c522018-12-06 11:56:27 +0100252function f_init_sgsap(charstring id) runs on MTC_CT {
253 id := id & "-SGsAP";
254 var SGsAPOps ops := {
255 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200256 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100257 }
258 var SGsAP_conn_parameters pars := {
259 remote_ip := mp_msc_ip,
260 remote_sctp_port := 29118,
261 local_ip := "",
262 local_sctp_port := -1
263 }
264
265 vc_SGsAP := SGsAP_Emulation_CT.create(id);
266 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
267 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
268}
269
270
Harald Weltea49e36e2018-01-21 19:29:33 +0100271function f_init_gsup(charstring id) runs on MTC_CT {
272 id := id & "-GSUP";
273 var GsupOps ops := {
274 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
275 }
276
277 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
278 vc_GSUP := GSUP_Emulation_CT.create(id);
279
280 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
281 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
282 /* we use this hack to get events like ASP_IPA_EVENT_UP */
283 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
284
285 vc_GSUP.start(GSUP_Emulation.main(ops, id));
286 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
287
288 /* wait for incoming connection to GSUP port before proceeding */
289 timer T := 10.0;
290 T.start;
291 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700292 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100293 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100294 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200295 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100296 }
297 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100298}
299
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200300function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100301
302 if (g_initialized == true) {
303 return;
304 }
305 g_initialized := true;
306
Philipp Maier75932982018-03-27 14:52:35 +0200307 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200308 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200309 }
310
311 for (var integer i := 0; i < num_bsc; i := i + 1) {
312 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200313 var RanOps ranops := BSC_RanOps;
314 ranops.use_osmux := osmux;
315 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200316 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200317 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200318 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200319 }
320 }
321
Harald Weltea49e36e2018-01-21 19:29:33 +0100322 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
323 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100324 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200325
326 if (gsup == true) {
327 f_init_gsup("MSC_Test");
328 }
Harald Weltef640a012018-04-14 17:49:21 +0200329 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100330
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100331 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100332 f_init_sgsap("MSC_Test");
333 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100334
335 map(self:MSCVTY, system:MSCVTY);
336 f_vty_set_prompts(MSCVTY);
337 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100338
339 /* set some defaults */
340 f_vty_config(MSCVTY, "network", "authentication optional");
341 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200342 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100343 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100344 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
345 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200346 if (mp_enable_osmux_test) {
347 if (osmux) {
348 f_vty_config(MSCVTY, "msc", "osmux on");
349 } else {
350 f_vty_config(MSCVTY, "msc", "osmux off");
351 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200352 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100353}
354
Philipp Maier328d1662018-03-07 10:40:27 +0100355/* Initialize for a direct connection to BSSAP. This function is an alternative
356 * to f_init() when the high level functions of the BSC_ConnectionHandler are
357 * not needed. */
358function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200359 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200360 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100361
362 /* Start guard timer and activate it as default */
363 Tguard_direct.start
364 activate(as_Tguard_direct());
365}
366
Harald Weltea49e36e2018-01-21 19:29:33 +0100367type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100368
Harald Weltea49e36e2018-01-21 19:29:33 +0100369/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200370function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100371 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200372runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100373 var BSC_ConnHdlrNetworkPars net_pars := {
374 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
375 expect_tmsi := true,
376 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200377 expect_ciph := false,
378 expect_imei := false,
379 expect_imei_early := false,
380 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
381 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100382 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100383 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200384 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
385 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100386 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100387 imei := f_gen_imei(imsi_suffix),
388 imsi := f_gen_imsi(imsi_suffix),
389 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100390 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100391 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100392 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100393 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100394 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100395 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100396 send_early_cm := true,
397 ipa_ctrl_ip := mp_msc_ip,
398 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100399 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100400 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200401 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200402 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100403 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200404 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200405 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200406 ran_is_geran := ran_is_geran,
407 use_osmux := use_osmux
Harald Weltea49e36e2018-01-21 19:29:33 +0100408 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200409 if (not ran_is_geran) {
410 pars.use_umts_aka := true;
411 pars.net.expect_auth := true;
412 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100413 return pars;
414}
415
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200416function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100417 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200418 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100419
420 vc_conn := BSC_ConnHdlr.create(id);
421 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200422 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
423 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100424 /* MNCC part */
425 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
426 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100427 /* MGCP part */
428 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
429 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100430 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200431 if (pars.gsup_enable == true) {
432 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
433 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
434 }
Harald Weltef640a012018-04-14 17:49:21 +0200435 /* SMPP part */
436 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
437 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100438 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100439 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100440 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
441 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
442 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100443
Harald Weltea10db902018-01-27 12:44:49 +0100444 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
445 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100446 vc_conn.start(derefers(fn)(id, pars));
447 return vc_conn;
448}
449
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200450function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false)
Harald Welte9b751a62019-04-14 17:39:29 +0200451runs on MTC_CT return BSC_ConnHdlr {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200452 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100453}
454
Harald Weltea49e36e2018-01-21 19:29:33 +0100455private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100456 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100457 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100458}
Harald Weltea49e36e2018-01-21 19:29:33 +0100459testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
460 var BSC_ConnHdlr vc_conn;
461 f_init();
462
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100463 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100464 vc_conn.done;
465}
466
467private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100468 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100469 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100470 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100471}
Harald Weltea49e36e2018-01-21 19:29:33 +0100472testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
473 var BSC_ConnHdlr vc_conn;
474 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100475 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100476
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100477 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100478 vc_conn.done;
479}
480
481/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200482friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100483 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100484 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
485
486 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200487 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100488 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100489 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
490 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
491 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100492 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
493 f_expect_clear();
494 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100495 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
496 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200497 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100498 }
499 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100500}
501testcase TC_lu_imsi_reject() runs on MTC_CT {
502 var BSC_ConnHdlr vc_conn;
503 f_init();
504
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100505 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100506 vc_conn.done;
507}
508
Harald Weltee13cfb22019-04-23 16:52:02 +0200509
510
Harald Weltea49e36e2018-01-21 19:29:33 +0100511/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200512friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100513 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100514 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
515
516 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200517 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100518 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100519 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
520 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
521 alt {
522 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100523 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
524 f_expect_clear();
525 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100526 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
527 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200528 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100529 }
530 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100531}
532testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
533 var BSC_ConnHdlr vc_conn;
534 f_init();
535
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100536 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100537 vc_conn.done;
538}
539
Harald Weltee13cfb22019-04-23 16:52:02 +0200540
Harald Welte7b1b2812018-01-22 21:23:06 +0100541private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100542 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100543 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100544 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100545}
546testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
547 var BSC_ConnHdlr vc_conn;
548 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100549 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100550
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100551 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100552 vc_conn.done;
553}
554
Harald Weltee13cfb22019-04-23 16:52:02 +0200555
556friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200557 pars.net.expect_auth := true;
558 pars.use_umts_aka := true;
559 f_init_handler(pars);
560 f_perform_lu();
561}
562testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
563 var BSC_ConnHdlr vc_conn;
564 f_init();
565 f_vty_config(MSCVTY, "network", "authentication required");
566
567 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
568 vc_conn.done;
569}
Harald Weltea49e36e2018-01-21 19:29:33 +0100570
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100571/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
572 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
573 */
574friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
575
576 f_init_handler(pars);
577
578 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
579 var PDU_DTAP_MT dtap_mt;
580
581 /* tell GSUP dispatcher to send this IMSI to us */
582 f_create_gsup_expect(hex2str(g_pars.imsi));
583
584 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
585 if (g_pars.ran_is_geran) {
586 f_bssap_compl_l3(l3_lu);
587 if (g_pars.send_early_cm) {
588 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
589 }
590 } else {
591 f_ranap_initial_ue(l3_lu);
592 }
593
594 f_mm_imei_early();
595 f_mm_common();
596 f_msc_lu_hlr();
597 f_mm_imei();
598
599 alt {
600 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
601 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
602 setverdict(fail, "Expected LU ACK, but received LU REJ");
603 mtc.stop;
604 }
605 }
606
607 /* currently (due to bug OS#4337), an extra LU reject is received before
608 terminating the connection. Enabling following line makes the test
609 pass: */
610 //f_expect_lu_reject('16'O); /* Cause: congestion */
611
612 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
613 extra time to avoid race conditons... */
614 f_expect_clear(7.0);
615
616 setverdict(pass);
617}
618testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
619 var BSC_ConnHdlr vc_conn;
620 f_init();
621
622 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
623 vc_conn.done;
624}
625
Harald Weltee13cfb22019-04-23 16:52:02 +0200626
Harald Weltea49e36e2018-01-21 19:29:33 +0100627/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200628friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100629runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100630 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100631
632 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100633 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100634 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100635
636 f_create_gsup_expect(hex2str(g_pars.imsi));
637
638 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200639 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200640 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100641
642 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100643 T.start;
644 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100645 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
646 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200647 [] BSSAP.receive {
648 setverdict(fail, "Received unexpected BSSAP");
649 mtc.stop;
650 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100651 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
652 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200653 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100654 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200655 [] T.timeout {
656 setverdict(fail, "Timeout waiting for CM SERV REQ");
657 mtc.stop;
658 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100659 }
660
Harald Welte1ddc7162018-01-27 14:25:46 +0100661 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100662}
Harald Weltea49e36e2018-01-21 19:29:33 +0100663testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
664 var BSC_ConnHdlr vc_conn;
665 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100666 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100667 vc_conn.done;
668}
669
Harald Weltee13cfb22019-04-23 16:52:02 +0200670
671friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100672 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200673 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100674 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100675 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100676}
677testcase TC_lu_and_mo_call() runs on MTC_CT {
678 var BSC_ConnHdlr vc_conn;
679 f_init();
680
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100681 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100682 vc_conn.done;
683}
684
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100685/* Verify T(iar) triggers and releases the channel */
686friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
687 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
688 f_init_handler(pars);
689 var CallParameters cpars := valueof(t_CallParams);
690 f_perform_lu();
691 f_mo_call_establish(cpars);
692
693 /* Expect the channel cleared upon T(iar) triggered: */
694 T_wait_iar.start;
695 alt {
696 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
697 T_wait_iar.stop
698 setverdict(pass);
699 }
700 [] MGCP.receive(tr_DLCX(?)) { repeat; }
701 [] T_wait_iar.timeout {
702 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
703 mtc.stop;
704 }
705 }
706
707 setverdict(pass);
708}
709testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
710 var BSC_ConnHdlr vc_conn;
711
712 /* Set T(iar) in MSC low enough that it will trigger before other side
713 has time to keep alive with a T(ias). Keep recommended ratio of
714 T(iar) >= T(ias)*2 */
715 g_msc_sccp_timer_ias := 2;
716 g_msc_sccp_timer_iar := 5;
717
718 f_init();
719
720 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
721 vc_conn.done;
722}
723
Harald Weltee13cfb22019-04-23 16:52:02 +0200724
Harald Welte071ed732018-01-23 19:53:52 +0100725/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200726friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100727 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100728
729 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
730 var PDU_DTAP_MT dtap_mt;
731
732 /* tell GSUP dispatcher to send this IMSI to us */
733 f_create_gsup_expect(hex2str(g_pars.imsi));
734
735 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200736 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100737
738 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200739 if (pars.ran_is_geran) {
740 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
741 }
Harald Welte071ed732018-01-23 19:53:52 +0100742
743 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
744 /* The HLR would normally return an auth vector here, but we fail to do so. */
745
746 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100747 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100748}
749testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
750 var BSC_ConnHdlr vc_conn;
751 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100752 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100753
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100754 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100755 vc_conn.done;
756}
757
Harald Weltee13cfb22019-04-23 16:52:02 +0200758
Harald Welte071ed732018-01-23 19:53:52 +0100759/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200760friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100761 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100762
763 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
764 var PDU_DTAP_MT dtap_mt;
765
766 /* tell GSUP dispatcher to send this IMSI to us */
767 f_create_gsup_expect(hex2str(g_pars.imsi));
768
769 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200770 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100771
772 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200773 if (pars.ran_is_geran) {
774 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
775 }
Harald Welte071ed732018-01-23 19:53:52 +0100776
777 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
778 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
779
780 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100781 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100782}
783testcase TC_lu_auth_sai_err() runs on MTC_CT {
784 var BSC_ConnHdlr vc_conn;
785 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100786 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100787
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100788 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100789 vc_conn.done;
790}
Harald Weltea49e36e2018-01-21 19:29:33 +0100791
Harald Weltee13cfb22019-04-23 16:52:02 +0200792
Harald Weltebc881782018-01-23 20:09:15 +0100793/* Test LU but BSC will send a clear request in the middle */
794private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100795 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100796
797 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
798 var PDU_DTAP_MT dtap_mt;
799
800 /* tell GSUP dispatcher to send this IMSI to us */
801 f_create_gsup_expect(hex2str(g_pars.imsi));
802
803 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200804 f_cl3_or_initial_ue(l3_lu);
Harald Weltebc881782018-01-23 20:09:15 +0100805
806 /* Send Early Classmark, just for the fun of it */
807 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
808
809 f_sleep(1.0);
810 /* send clear request in the middle of the LU */
811 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200812 alt {
813 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
814 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
815 }
Harald Weltebc881782018-01-23 20:09:15 +0100816 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100817 alt {
818 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200819 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
820 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200821 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200822 repeat;
823 }
Harald Welte6811d102019-04-14 22:23:14 +0200824 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100825 }
Harald Weltebc881782018-01-23 20:09:15 +0100826 setverdict(pass);
827}
828testcase TC_lu_clear_request() runs on MTC_CT {
829 var BSC_ConnHdlr vc_conn;
830 f_init();
831
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100832 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100833 vc_conn.done;
834}
835
Harald Welte66af9e62018-01-24 17:28:21 +0100836/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200837friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100838 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100839
840 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
841 var PDU_DTAP_MT dtap_mt;
842
843 /* tell GSUP dispatcher to send this IMSI to us */
844 f_create_gsup_expect(hex2str(g_pars.imsi));
845
846 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200847 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100848
849 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200850 if (pars.ran_is_geran) {
851 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
852 }
Harald Welte66af9e62018-01-24 17:28:21 +0100853
854 f_sleep(1.0);
855 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200856 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100857 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100858 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100859}
860testcase TC_lu_disconnect() runs on MTC_CT {
861 var BSC_ConnHdlr vc_conn;
862 f_init();
863
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100864 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100865 vc_conn.done;
866}
867
Harald Welteba7b6d92018-01-23 21:32:34 +0100868/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200869friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100870 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100871
Harald Welte256571e2018-01-24 18:47:19 +0100872 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100873 var PDU_DTAP_MT dtap_mt;
874
875 /* tell GSUP dispatcher to send this IMSI to us */
876 f_create_gsup_expect(hex2str(g_pars.imsi));
877
878 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200879 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100880
881 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200882 if (pars.ran_is_geran) {
883 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
884 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100885 /* wait for LU reject, ignore any ID REQ */
886 alt {
887 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
888 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
889 }
890 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100891 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100892}
893testcase TC_lu_by_imei() runs on MTC_CT {
894 var BSC_ConnHdlr vc_conn;
895 f_init();
896
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100897 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100898 vc_conn.done;
899}
900
Harald Weltee13cfb22019-04-23 16:52:02 +0200901
Harald Welteba7b6d92018-01-23 21:32:34 +0100902/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
903private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200904 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
905 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100906 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100907
908 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
909 var PDU_DTAP_MT dtap_mt;
910
911 /* tell GSUP dispatcher to send this IMSI to us */
912 f_create_gsup_expect(hex2str(g_pars.imsi));
913
914 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200915 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100916
917 /* Send Early Classmark, just for the fun of it */
918 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
919
920 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +0200921 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200922 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100923 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
924
925 /* Expect MSC to do UpdateLocation to HLR; respond to it */
926 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
927 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
928 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
929 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
930
931 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100932 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
933 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
934 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100935 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
936 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200937 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100938 }
939 }
940
Philipp Maier9b690e42018-12-21 11:50:03 +0100941 /* Wait for MM-Information (if enabled) */
942 f_expect_mm_info();
943
Harald Welteba7b6d92018-01-23 21:32:34 +0100944 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100945 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100946}
947testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
948 var BSC_ConnHdlr vc_conn;
949 f_init();
950
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100951 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100952 vc_conn.done;
953}
954
955
Harald Welte45164da2018-01-24 12:51:27 +0100956/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200957friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100958 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100959
960 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
961
962 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200963 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100964
965 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200966 if (pars.ran_is_geran) {
967 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
968 }
Harald Welte45164da2018-01-24 12:51:27 +0100969
970 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100971 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100972}
973testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
974 var BSC_ConnHdlr vc_conn;
975 f_init();
976
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100977 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100978 vc_conn.done;
979}
980
Harald Weltee13cfb22019-04-23 16:52:02 +0200981
Harald Welte45164da2018-01-24 12:51:27 +0100982/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200983friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100984 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100985
986 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
987
988 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200989 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100990
991 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200992 if (pars.ran_is_geran) {
993 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
994 }
Harald Welte45164da2018-01-24 12:51:27 +0100995
996 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100997 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100998}
999testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1000 var BSC_ConnHdlr vc_conn;
1001 f_init();
1002
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001003 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +01001004 vc_conn.done;
1005}
1006
Harald Weltee13cfb22019-04-23 16:52:02 +02001007
Harald Welte45164da2018-01-24 12:51:27 +01001008/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001009friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001010 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001011
Harald Welte256571e2018-01-24 18:47:19 +01001012 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001013
1014 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001015 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001016
1017 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001018 if (pars.ran_is_geran) {
1019 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1020 }
Harald Welte45164da2018-01-24 12:51:27 +01001021
1022 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001023 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001024}
1025testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1026 var BSC_ConnHdlr vc_conn;
1027 f_init();
1028
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001029 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +01001030 vc_conn.done;
1031}
1032
1033
1034/* helper function for an emergency call. caller passes in mobile identity to use */
1035private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001036 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1037 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001038
Harald Welte0bef21e2018-02-10 09:48:23 +01001039 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001040}
1041
1042/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001043friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001044 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001045
Harald Welte256571e2018-01-24 18:47:19 +01001046 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001047 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001048 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001049 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001050 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001051}
1052testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1053 var BSC_ConnHdlr vc_conn;
1054 f_init();
1055
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001056 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001057 vc_conn.done;
1058}
1059
Harald Weltee13cfb22019-04-23 16:52:02 +02001060
Harald Welted5b91402018-01-24 18:48:16 +01001061/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001062friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001063 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001064 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001065 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001066 /* Then issue emergency call identified by IMSI */
1067 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1068}
1069testcase TC_emerg_call_imsi() runs on MTC_CT {
1070 var BSC_ConnHdlr vc_conn;
1071 f_init();
1072
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001073 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001074 vc_conn.done;
1075}
1076
Harald Weltee13cfb22019-04-23 16:52:02 +02001077
Harald Welte45164da2018-01-24 12:51:27 +01001078/* CM Service Request for VGCS -> reject */
1079private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001080 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001081
1082 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001083 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001084
1085 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001086 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001087 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001088 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001089 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001090}
1091testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1092 var BSC_ConnHdlr vc_conn;
1093 f_init();
1094
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001095 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001096 vc_conn.done;
1097}
1098
1099/* CM Service Request for VBS -> reject */
1100private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001101 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001102
1103 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001104 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001105
1106 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001107 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001108 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001109 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001110 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001111}
1112testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1113 var BSC_ConnHdlr vc_conn;
1114 f_init();
1115
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001116 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001117 vc_conn.done;
1118}
1119
1120/* CM Service Request for LCS -> reject */
1121private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001122 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001123
1124 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001125 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001126
1127 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001128 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001129 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001130 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001131 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001132}
1133testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1134 var BSC_ConnHdlr vc_conn;
1135 f_init();
1136
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001137 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001138 vc_conn.done;
1139}
1140
Harald Welte0195ab12018-01-24 21:50:20 +01001141/* CM Re-Establishment Request */
1142private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001143 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001144
1145 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001146 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001147
1148 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1149 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001150 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001151 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001152 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001153}
1154testcase TC_cm_reest_req_reject() runs on MTC_CT {
1155 var BSC_ConnHdlr vc_conn;
1156 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001157
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001158 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001159 vc_conn.done;
1160}
1161
Harald Weltec638f4d2018-01-24 22:00:36 +01001162/* Test LU (with authentication enabled), with wrong response from MS */
1163private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001164 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001165
1166 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1167
1168 /* tell GSUP dispatcher to send this IMSI to us */
1169 f_create_gsup_expect(hex2str(g_pars.imsi));
1170
1171 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001172 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001173
1174 /* Send Early Classmark, just for the fun of it */
1175 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1176
1177 var AuthVector vec := f_gen_auth_vec_2g();
1178 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1179 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1180 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1181
1182 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1183 /* Send back wrong auth response */
1184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1185
1186 /* Expect GSUP AUTH FAIL REP to HLR */
1187 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1188
1189 /* Expect LU REJECT with Cause == Illegal MS */
1190 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001191 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001192}
1193testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1194 var BSC_ConnHdlr vc_conn;
1195 f_init();
1196 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001197
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001198 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001199 vc_conn.done;
1200}
1201
Harald Weltede371492018-01-27 23:44:41 +01001202/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001203private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001204 pars.net.expect_auth := true;
1205 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001206 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001207 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001208}
1209testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1210 var BSC_ConnHdlr vc_conn;
1211 f_init();
1212 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001213 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1214
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001215 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001216 vc_conn.done;
1217}
1218
Harald Welte1af6ea82018-01-25 18:33:15 +01001219/* Test Complete L3 without payload */
1220private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001221 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001222
1223 /* Send Complete L3 Info with empty L3 frame */
1224 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1225 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1226
Harald Weltef466eb42018-01-27 14:26:54 +01001227 timer T := 5.0;
1228 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001229 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001230 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001231 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001232 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001233 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001234 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001235 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001236 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001237 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001238 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001239 }
1240 setverdict(pass);
1241}
1242testcase TC_cl3_no_payload() runs on MTC_CT {
1243 var BSC_ConnHdlr vc_conn;
1244 f_init();
1245
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001246 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001247 vc_conn.done;
1248}
1249
1250/* Test Complete L3 with random payload */
1251private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001252 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001253
Daniel Willmannaa14a382018-07-26 08:29:45 +02001254 /* length is limited by PDU_BSSAP length field which includes some
1255 * other fields beside l3info payload. So payl can only be 240 bytes
1256 * Since rnd() returns values < 1 multiply with 241
1257 */
1258 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001259 var octetstring payl := f_rnd_octstring(len);
1260
1261 /* Send Complete L3 Info with empty L3 frame */
1262 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1263 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1264
Harald Weltef466eb42018-01-27 14:26:54 +01001265 timer T := 5.0;
1266 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001267 alt {
1268 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001269 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001270 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001271 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001272 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001273 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001274 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001275 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001276 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001277 }
1278 setverdict(pass);
1279}
1280testcase TC_cl3_rnd_payload() runs on MTC_CT {
1281 var BSC_ConnHdlr vc_conn;
1282 f_init();
1283
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001284 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001285 vc_conn.done;
1286}
1287
Harald Welte116e4332018-01-26 22:17:48 +01001288/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001289friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001290 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001291
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001292 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001293
Harald Welteb9e86fa2018-04-09 18:18:31 +02001294 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001295 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001296}
1297testcase TC_establish_and_nothing() runs on MTC_CT {
1298 var BSC_ConnHdlr vc_conn;
1299 f_init();
1300
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001301 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001302 vc_conn.done;
1303}
1304
Harald Weltee13cfb22019-04-23 16:52:02 +02001305
Harald Welte12510c52018-01-26 22:26:24 +01001306/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001307friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001308 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001309
Harald Welte12510c52018-01-26 22:26:24 +01001310 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001311 cpars.mgw_conn_2.resp := 0;
1312 cpars.stop_after_cc_setup := true;
1313
1314 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001315
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001316 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001317
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001318 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001319
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001320 var default ccrel := activate(as_optional_cc_rel(cpars));
1321
Philipp Maier109e6aa2018-10-17 10:53:32 +02001322 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001323
1324 deactivate(ccrel);
1325
1326 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001327}
1328testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1329 var BSC_ConnHdlr vc_conn;
1330 f_init();
1331
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001332 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001333 vc_conn.done;
1334}
1335
Harald Weltee13cfb22019-04-23 16:52:02 +02001336
Harald Welte3ab88002018-01-26 22:37:25 +01001337/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001338friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001339 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001340 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1341 var MNCC_PDU mncc;
1342 var MgcpCommand mgcp_cmd;
1343
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001344 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001345 /* Do not respond to the second CRCX */
1346 cpars.mgw_conn_2.resp := 0;
1347 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001348
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001349 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001350
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001351 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001352
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001353 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001354}
1355testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1356 var BSC_ConnHdlr vc_conn;
1357 f_init();
1358
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001359 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001360 vc_conn.done;
1361}
1362
Harald Weltee13cfb22019-04-23 16:52:02 +02001363
Harald Welte0cc82d92018-01-26 22:52:34 +01001364/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001365friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001366 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001367
Harald Welte0cc82d92018-01-26 22:52:34 +01001368 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001369
1370 /* Respond with error for the first CRCX */
1371 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001372
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001373 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001374 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001375
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001376 var default ccrel := activate(as_optional_cc_rel(cpars));
1377 f_expect_clear(60.0);
1378 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001379}
1380testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1381 var BSC_ConnHdlr vc_conn;
1382 f_init();
1383
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001384 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001385 vc_conn.done;
1386}
1387
Harald Welte3ab88002018-01-26 22:37:25 +01001388
Harald Welte812f7a42018-01-27 00:49:18 +01001389/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1390private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1391 var MNCC_PDU mncc;
1392 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001393
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001394 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001395 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001396
1397 /* Allocate call reference and send SETUP via MNCC to MSC */
1398 cpars.mncc_callref := f_rnd_int(2147483648);
1399 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1400 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1401
1402 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001403 f_expect_paging();
1404
Harald Welte812f7a42018-01-27 00:49:18 +01001405 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001406 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001407
1408 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1409
1410 /* MSC->MS: SETUP */
1411 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1412}
1413
1414/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001415friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001416 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001417 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1418 var MNCC_PDU mncc;
1419 var MgcpCommand mgcp_cmd;
1420
1421 f_mt_call_start(cpars);
1422
1423 /* MS->MSC: CALL CONFIRMED */
1424 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1425
1426 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1427
1428 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1429 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001430
1431 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1432 * set an endpoint name that fits the pattern. If not, just use the
1433 * endpoint name from the request */
1434 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1435 cpars.mgcp_ep := "rtpbridge/1@mgw";
1436 } else {
1437 cpars.mgcp_ep := mgcp_cmd.line.ep;
1438 }
1439
Harald Welte812f7a42018-01-27 00:49:18 +01001440 /* Respond to CRCX with error */
1441 var MgcpResponse mgcp_rsp := {
1442 line := {
1443 code := "542",
1444 trans_id := mgcp_cmd.line.trans_id,
1445 string := "FORCED_FAIL"
1446 },
Harald Welte812f7a42018-01-27 00:49:18 +01001447 sdp := omit
1448 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001449 var MgcpParameter mgcp_rsp_param := {
1450 code := "Z",
1451 val := cpars.mgcp_ep
1452 };
1453 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001454 MGCP.send(mgcp_rsp);
1455
1456 timer T := 30.0;
1457 T.start;
1458 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001459 [] T.timeout {
1460 setverdict(fail, "Timeout waiting for channel release");
1461 mtc.stop;
1462 }
Harald Welte812f7a42018-01-27 00:49:18 +01001463 [] MNCC.receive { repeat; }
1464 [] GSUP.receive { repeat; }
1465 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1466 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1467 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1468 repeat;
1469 }
1470 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001471 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001472 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001473 }
1474}
1475testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1476 var BSC_ConnHdlr vc_conn;
1477 f_init();
1478
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001479 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001480 vc_conn.done;
1481}
1482
1483
Harald Weltee13cfb22019-04-23 16:52:02 +02001484
Harald Welte812f7a42018-01-27 00:49:18 +01001485/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001486friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001487 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001488 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1489 var MNCC_PDU mncc;
1490 var MgcpCommand mgcp_cmd;
1491
1492 f_mt_call_start(cpars);
1493
1494 /* MS->MSC: CALL CONFIRMED */
1495 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1496 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1497
1498 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1499 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1500 cpars.mgcp_ep := mgcp_cmd.line.ep;
1501 /* FIXME: Respond to CRCX */
1502
1503 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1504 timer T := 190.0;
1505 T.start;
1506 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001507 [] T.timeout {
1508 setverdict(fail, "Timeout waiting for T310");
1509 mtc.stop;
1510 }
Harald Welte812f7a42018-01-27 00:49:18 +01001511 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1512 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1513 }
1514 }
1515 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1516 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1517 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1518 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1519
1520 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001521 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1522 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1523 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1524 repeat;
1525 }
Harald Welte5946b332018-03-18 23:32:21 +01001526 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001527 }
1528}
1529testcase TC_mt_t310() runs on MTC_CT {
1530 var BSC_ConnHdlr vc_conn;
1531 f_init();
1532
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001533 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001534 vc_conn.done;
1535}
1536
Harald Weltee13cfb22019-04-23 16:52:02 +02001537
Harald Welte167458a2018-01-27 15:58:16 +01001538/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001539friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001540 f_init_handler(pars);
1541 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001542
1543 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001544 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001545
1546 /* First MO call should succeed */
1547 f_mo_call(cpars);
1548
1549 /* Cancel the subscriber in the VLR */
1550 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1551 alt {
1552 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1553 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1554 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001555 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001556 }
1557 }
1558
1559 /* Follow-up transactions should fail */
1560 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1561 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001562 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001563 alt {
1564 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1565 [] BSSAP.receive {
1566 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001567 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001568 }
1569 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001570
1571 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001572 setverdict(pass);
1573}
1574testcase TC_gsup_cancel() runs on MTC_CT {
1575 var BSC_ConnHdlr vc_conn;
1576 f_init();
1577
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001578 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001579 vc_conn.done;
1580}
1581
Harald Weltee13cfb22019-04-23 16:52:02 +02001582
Harald Welte9de84792018-01-28 01:06:35 +01001583/* A5/1 only permitted on network side, and MS capable to do it */
1584private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1585 pars.net.expect_auth := true;
1586 pars.net.expect_ciph := true;
1587 pars.net.kc_support := '02'O; /* A5/1 only */
1588 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001589 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001590}
1591testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1592 var BSC_ConnHdlr vc_conn;
1593 f_init();
1594 f_vty_config(MSCVTY, "network", "authentication required");
1595 f_vty_config(MSCVTY, "network", "encryption a5 1");
1596
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001597 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001598 vc_conn.done;
1599}
1600
1601/* A5/3 only permitted on network side, and MS capable to do it */
1602private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1603 pars.net.expect_auth := true;
1604 pars.net.expect_ciph := true;
1605 pars.net.kc_support := '08'O; /* A5/3 only */
1606 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001607 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001608}
1609testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1610 var BSC_ConnHdlr vc_conn;
1611 f_init();
1612 f_vty_config(MSCVTY, "network", "authentication required");
1613 f_vty_config(MSCVTY, "network", "encryption a5 3");
1614
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001615 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001616 vc_conn.done;
1617}
1618
1619/* A5/3 only permitted on network side, and MS with only A5/1 support */
1620private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1621 pars.net.expect_auth := true;
1622 pars.net.expect_ciph := true;
1623 pars.net.kc_support := '08'O; /* A5/3 only */
1624 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1625 f_init_handler(pars, 15.0);
1626
1627 /* cannot use f_perform_lu() as we expect a reject */
1628 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1629 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001630 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001631 if (pars.send_early_cm) {
1632 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1633 } else {
1634 pars.cm1.esind := '0'B;
1635 }
Harald Welte9de84792018-01-28 01:06:35 +01001636 f_mm_auth();
1637 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001638 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1639 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1640 repeat;
1641 }
Harald Welte5946b332018-03-18 23:32:21 +01001642 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1643 f_expect_clear();
1644 }
Harald Welte9de84792018-01-28 01:06:35 +01001645 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1646 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001647 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001648 }
1649 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001650 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001651 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001652 }
1653 }
1654 setverdict(pass);
1655}
1656testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1657 var BSC_ConnHdlr vc_conn;
1658 f_init();
1659 f_vty_config(MSCVTY, "network", "authentication required");
1660 f_vty_config(MSCVTY, "network", "encryption a5 3");
1661
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001662 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1663 vc_conn.done;
1664}
1665testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1666 var BSC_ConnHdlrPars pars;
1667 var BSC_ConnHdlr vc_conn;
1668 f_init();
1669 f_vty_config(MSCVTY, "network", "authentication required");
1670 f_vty_config(MSCVTY, "network", "encryption a5 3");
1671
1672 pars := f_init_pars(361);
1673 pars.send_early_cm := false;
1674 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001675 vc_conn.done;
1676}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001677testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1678 var BSC_ConnHdlr vc_conn;
1679 f_init();
1680 f_vty_config(MSCVTY, "network", "authentication required");
1681 f_vty_config(MSCVTY, "network", "encryption a5 3");
1682
1683 /* Make sure the MSC category is on DEBUG level to trigger the log
1684 * message that is reported in OS#2947 to trigger the segfault */
1685 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1686
1687 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1688 vc_conn.done;
1689}
Harald Welte9de84792018-01-28 01:06:35 +01001690
1691/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1692private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1693 pars.net.expect_auth := true;
1694 pars.net.expect_ciph := true;
1695 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1696 pars.cm1.a5_1 := '1'B;
1697 pars.cm2.a5_1 := '1'B;
1698 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1699 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1700 f_init_handler(pars, 15.0);
1701
1702 /* cannot use f_perform_lu() as we expect a reject */
1703 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1704 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001705 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001706 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1707 f_mm_auth();
1708 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001709 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1710 f_expect_clear();
1711 }
Harald Welte9de84792018-01-28 01:06:35 +01001712 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1713 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001714 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001715 }
1716 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001717 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001718 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001719 }
1720 }
1721 setverdict(pass);
1722}
1723testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1724 var BSC_ConnHdlr vc_conn;
1725 f_init();
1726 f_vty_config(MSCVTY, "network", "authentication required");
1727 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1728
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001729 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001730 vc_conn.done;
1731}
1732
1733/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1734private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1735 pars.net.expect_auth := true;
1736 pars.net.expect_ciph := true;
1737 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1738 pars.cm1.a5_1 := '1'B;
1739 pars.cm2.a5_1 := '1'B;
1740 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1741 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1742 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001743 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001744}
1745testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1746 var BSC_ConnHdlr vc_conn;
1747 f_init();
1748 f_vty_config(MSCVTY, "network", "authentication required");
1749 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1750
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001751 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001752 vc_conn.done;
1753}
1754
Harald Welte33ec09b2018-02-10 15:34:46 +01001755/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001756friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001757 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001758 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001759 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001760
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001761 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001762 f_mt_call(cpars);
1763}
1764testcase TC_lu_and_mt_call() runs on MTC_CT {
1765 var BSC_ConnHdlr vc_conn;
1766 f_init();
1767
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001768 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001769 vc_conn.done;
1770}
1771
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001772testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1773 var BSC_ConnHdlr vc_conn;
1774 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001775
1776 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1777 vc_conn.done;
1778}
1779
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01001780/* MT call while already Paging */
1781friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1782 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1783 var SmsParameters spars := valueof(t_SmsPars);
1784 var OCT4 tmsi;
1785
1786 f_init_handler(pars);
1787
1788 /* Perform location update */
1789 f_perform_lu();
1790
1791 /* register an 'expect' for given IMSI (+TMSI) */
1792 if (isvalue(g_pars.tmsi)) {
1793 tmsi := g_pars.tmsi;
1794 } else {
1795 tmsi := 'FFFFFFFF'O;
1796 }
1797 f_ran_register_imsi(g_pars.imsi, tmsi);
1798
1799 log("start Paging by an SMS");
1800 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
1801
1802 /* MSC->BSC: expect PAGING from MSC */
1803 f_expect_paging();
1804
1805 log("MNCC signals MT call, before Paging Response");
1806 f_mt_call_initate(cpars);
1807 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
1808
1809 f_sleep(0.5);
1810 log("phone answers Paging, expecting both SMS and MT call to be established");
1811 f_establish_fully(EST_TYPE_PAG_RESP);
1812 spars.tp.ud := 'C8329BFD064D9B53'O;
1813 interleave {
1814 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
1815 log("Got SMS-DELIVER");
1816 };
1817 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
1818 log("Got CC Setup");
1819 };
1820 }
1821 setverdict(pass);
1822 log("success, tear down");
1823 var default ccrel := activate(as_optional_cc_rel(cpars));
1824 if (g_pars.ran_is_geran) {
1825 BSSAP.send(ts_BSSMAP_ClearRequest(0));
1826 } else {
1827 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
1828 }
1829 f_expect_clear();
1830 deactivate(ccrel);
1831 f_vty_sms_clear(hex2str(g_pars.imsi));
1832}
1833testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
1834 var BSC_ConnHdlrPars pars;
1835 var BSC_ConnHdlr vc_conn;
1836 f_init();
1837 pars := f_init_pars(391);
1838 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
1839 vc_conn.done;
1840}
1841
Daniel Willmann8b084372018-02-04 13:35:26 +01001842/* Test MO Call SETUP with DTMF */
1843private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1844 f_init_handler(pars);
1845 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01001846
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001847 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001848 f_mo_seq_dtmf_dup(cpars);
1849}
1850testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1851 var BSC_ConnHdlr vc_conn;
1852 f_init();
1853
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001854 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001855 vc_conn.done;
1856}
Harald Welte9de84792018-01-28 01:06:35 +01001857
Philipp Maier328d1662018-03-07 10:40:27 +01001858testcase TC_cr_before_reset() runs on MTC_CT {
1859 timer T := 4.0;
1860 var boolean reset_ack_seen := false;
1861 f_init_bssap_direct();
1862
Harald Welte3ca0ce12019-04-23 17:18:48 +02001863 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001864
Daniel Willmanne8018962018-08-21 14:18:00 +02001865 f_sleep(3.0);
1866
Philipp Maier328d1662018-03-07 10:40:27 +01001867 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001868 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001869
1870 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001871 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001872 T.start
1873 alt {
1874 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1875 reset_ack_seen := true;
1876 repeat;
1877 }
1878
1879 /* Acknowledge MSC sided reset requests */
1880 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001881 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001882 repeat;
1883 }
1884
1885 /* Ignore all other messages (e.g CR from the connection request) */
1886 [] BSSAP_DIRECT.receive { repeat }
1887
1888 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1889 * deadlock situation. The MSC is then unable to respond to any
1890 * further BSSMAP RESET or any other sort of traffic. */
1891 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1892 [reset_ack_seen == false] T.timeout {
1893 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001894 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001895 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01001896 }
Philipp Maier328d1662018-03-07 10:40:27 +01001897}
Harald Welte9de84792018-01-28 01:06:35 +01001898
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001899/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001900friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001901 f_init_handler(pars);
1902 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1903 var MNCC_PDU mncc;
1904 var MgcpCommand mgcp_cmd;
1905
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001906 /* Do not respond to the second CRCX */
1907 cpars.mgw_conn_2.resp := 0;
1908
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001909 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001910 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001911
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001912 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001913
1914 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001915
1916 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001917}
1918testcase TC_mo_release_timeout() runs on MTC_CT {
1919 var BSC_ConnHdlr vc_conn;
1920 f_init();
1921
1922 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1923 vc_conn.done;
1924}
1925
Harald Welte12510c52018-01-26 22:26:24 +01001926
Philipp Maier2a98a732018-03-19 16:06:12 +01001927/* LU followed by MT call (including paging) */
1928private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1929 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001930 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001931
1932 /* Intentionally disable the CRCX response */
1933 cpars.mgw_drop_dlcx := true;
1934
1935 /* Perform location update and call */
1936 f_perform_lu();
1937 f_mt_call(cpars);
1938}
1939testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1940 var BSC_ConnHdlr vc_conn;
1941 f_init();
1942
1943 /* Perform an almost normal looking locationupdate + mt-call, but do
1944 * not respond to the DLCX at the end of the call */
1945 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1946 vc_conn.done;
1947
1948 /* Wait a guard period until the MGCP layer in the MSC times out,
1949 * if the MSC is vulnerable to the use-after-free situation that is
1950 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1951 * segfault now */
1952 f_sleep(6.0);
1953
1954 /* Run the init procedures once more. If the MSC has crashed, this
1955 * this will fail */
1956 f_init();
1957}
Harald Welte45164da2018-01-24 12:51:27 +01001958
Philipp Maier75932982018-03-27 14:52:35 +02001959/* Two BSSMAP resets from two different BSCs */
1960testcase TC_reset_two() runs on MTC_CT {
1961 var BSC_ConnHdlr vc_conn;
1962 f_init(2);
1963 f_sleep(2.0);
1964 setverdict(pass);
1965}
1966
Harald Weltee13cfb22019-04-23 16:52:02 +02001967/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
1968testcase TC_reset_two_1iu() runs on MTC_CT {
1969 var BSC_ConnHdlr vc_conn;
1970 f_init(3);
1971 f_sleep(2.0);
1972 setverdict(pass);
1973}
1974
Harald Weltef640a012018-04-14 17:49:21 +02001975/***********************************************************************
1976 * SMS Testing
1977 ***********************************************************************/
1978
Harald Weltef45efeb2018-04-09 18:19:24 +02001979/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001980friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001981 var SmsParameters spars := valueof(t_SmsPars);
1982
1983 f_init_handler(pars);
1984
1985 /* Perform location update and call */
1986 f_perform_lu();
1987
1988 f_establish_fully(EST_TYPE_MO_SMS);
1989
1990 //spars.exp_rp_err := 96; /* invalid mandatory information */
1991 f_mo_sms(spars);
1992
1993 f_expect_clear();
1994}
1995testcase TC_lu_and_mo_sms() runs on MTC_CT {
1996 var BSC_ConnHdlr vc_conn;
1997 f_init();
1998 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1999 vc_conn.done;
2000}
2001
Harald Weltee13cfb22019-04-23 16:52:02 +02002002
Harald Weltef45efeb2018-04-09 18:19:24 +02002003private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002004runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002005 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2006}
2007
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002008/* Remove still pending SMS */
2009private function f_vty_sms_clear(charstring imsi)
2010runs on BSC_ConnHdlr {
2011 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2012 f_vty_transceive(MSCVTY, "sms-queue clear");
2013}
2014
Harald Weltef45efeb2018-04-09 18:19:24 +02002015/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002016friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002017 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002018
2019 f_init_handler(pars);
2020
2021 /* Perform location update and call */
2022 f_perform_lu();
2023
2024 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002025 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002026
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002027 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002028
2029 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002030 f_expect_paging();
2031
Harald Weltef45efeb2018-04-09 18:19:24 +02002032 /* Establish DTAP / BSSAP / SCCP connection */
2033 f_establish_fully(EST_TYPE_PAG_RESP);
2034
2035 spars.tp.ud := 'C8329BFD064D9B53'O;
2036 f_mt_sms(spars);
2037
2038 f_expect_clear();
2039}
2040testcase TC_lu_and_mt_sms() runs on MTC_CT {
2041 var BSC_ConnHdlrPars pars;
2042 var BSC_ConnHdlr vc_conn;
2043 f_init();
2044 pars := f_init_pars(43);
2045 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002046 vc_conn.done;
2047}
2048
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002049/* SMS added while already Paging */
2050friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2051 var SmsParameters spars := valueof(t_SmsPars);
2052 var OCT4 tmsi;
2053
2054 f_init_handler(pars);
2055
2056 f_perform_lu();
2057
2058 /* register an 'expect' for given IMSI (+TMSI) */
2059 if (isvalue(g_pars.tmsi)) {
2060 tmsi := g_pars.tmsi;
2061 } else {
2062 tmsi := 'FFFFFFFF'O;
2063 }
2064 f_ran_register_imsi(g_pars.imsi, tmsi);
2065
2066 log("first SMS");
2067 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2068
2069 /* MSC->BSC: expect PAGING from MSC */
2070 f_expect_paging();
2071
2072 log("second SMS");
2073 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2074 * with the pending paging. Another SMS: */
2075 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2076
2077 /* Establish DTAP / BSSAP / SCCP connection */
2078 f_establish_fully(EST_TYPE_PAG_RESP);
2079
2080 spars.tp.ud := 'C8329BFD064D9B53'O;
2081 f_mt_sms(spars);
2082
2083 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2084 f_mt_sms(spars);
2085
2086 f_expect_clear();
2087}
2088testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2089 var BSC_ConnHdlrPars pars;
2090 var BSC_ConnHdlr vc_conn;
2091 f_init();
2092 pars := f_init_pars(44);
2093 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2094 vc_conn.done;
2095}
Harald Weltee13cfb22019-04-23 16:52:02 +02002096
Philipp Maier3983e702018-11-22 19:01:33 +01002097/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002098friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002099 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002100
Philipp Maier3983e702018-11-22 19:01:33 +01002101 f_init_handler(pars, 150.0);
2102
2103 /* Perform location update */
2104 f_perform_lu();
2105
2106 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002107 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002108
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002109 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2110
Neels Hofmeyr16237742019-03-06 15:34:01 +01002111 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002112 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002113
2114 /* Wait some time to make sure the MSC is not delivering any further
2115 * paging messages or anything else that could be unexpected. */
2116 timer T := 20.0;
2117 T.start
2118 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002119 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2120 setverdict(fail, "paging seems not to stop!");
2121 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002122 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002123 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2124 setverdict(fail, "paging seems not to stop!");
2125 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002126 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002127 [] BSSAP.receive {
2128 setverdict(fail, "unexpected BSSAP message received");
2129 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002130 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002131 [] T.timeout {
2132 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002133 }
2134 }
2135
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002136 f_vty_sms_clear(hex2str(g_pars.imsi));
2137
Philipp Maier3983e702018-11-22 19:01:33 +01002138 setverdict(pass);
2139}
2140testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2141 var BSC_ConnHdlrPars pars;
2142 var BSC_ConnHdlr vc_conn;
2143 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002144 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002145 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002146 vc_conn.done;
2147}
2148
Alexander Couzensfc02f242019-09-12 03:43:18 +02002149/* LU followed by MT SMS with repeated paging */
2150friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2151 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002152
2153 f_init_handler(pars);
2154
2155 /* Perform location update and call */
2156 f_perform_lu();
2157
2158 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002159 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002160
2161 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2162
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002163 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002164 /* MSC->BSC: expect PAGING from MSC */
2165 f_expect_paging();
2166
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002167 if (g_pars.ran_is_geran) {
2168 log("GERAN: expect no further Paging");
2169 } else {
2170 log("UTRAN: expect more Paging");
2171 }
2172
2173 timer T := 5.0;
2174 T.start;
2175 alt {
2176 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2177 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2178 mtc.stop;
2179 }
2180 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2181 log("UTRAN: second Paging received, as expected");
2182 setverdict(pass);
2183 }
2184 [] T.timeout {
2185 if (g_pars.ran_is_geran) {
2186 log("GERAN: No further Paging received, as expected");
2187 setverdict(pass);
2188 } else {
2189 setverdict(fail, "UTRAN: Expected a second Paging");
2190 mtc.stop;
2191 }
2192 }
2193 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002194
2195 /* Establish DTAP / BSSAP / SCCP connection */
2196 f_establish_fully(EST_TYPE_PAG_RESP);
2197
2198 spars.tp.ud := 'C8329BFD064D9B53'O;
2199 f_mt_sms(spars);
2200
2201 f_expect_clear();
2202}
2203testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2204 var BSC_ConnHdlrPars pars;
2205 var BSC_ConnHdlr vc_conn;
2206 f_init();
2207 pars := f_init_pars(1844);
2208 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2209 vc_conn.done;
2210}
Harald Weltee13cfb22019-04-23 16:52:02 +02002211
Harald Weltef640a012018-04-14 17:49:21 +02002212/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002213friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002214 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002215
Harald Weltef640a012018-04-14 17:49:21 +02002216 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002217
Harald Weltef640a012018-04-14 17:49:21 +02002218 /* Perform location update so IMSI is known + registered in MSC/VLR */
2219 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002220
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002221 /* MS/UE submits a MO SMS */
2222 f_establish_fully(EST_TYPE_MO_SMS);
2223 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002224
2225 var SMPP_PDU smpp;
2226 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2227 tr_smpp.body.deliver_sm := {
2228 service_type := "CMT",
2229 source_addr_ton := network_specific,
2230 source_addr_npi := isdn,
2231 source_addr := hex2str(pars.msisdn),
2232 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2233 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2234 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2235 esm_class := '00000001'B,
2236 protocol_id := 0,
2237 priority_flag := 0,
2238 schedule_delivery_time := "",
2239 replace_if_present := 0,
2240 data_coding := '00000001'B,
2241 sm_default_msg_id := 0,
2242 sm_length := ?,
2243 short_message := spars.tp.ud,
2244 opt_pars := {
2245 {
2246 tag := user_message_reference,
2247 len := 2,
2248 opt_value := {
2249 int2_val := oct2int(spars.tp.msg_ref)
2250 }
2251 }
2252 }
2253 };
2254 alt {
2255 [] SMPP.receive(tr_smpp) -> value smpp {
2256 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2257 }
2258 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2259 }
2260
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002261 /* MSC terminates the SMS transaction with RP-ACK */
2262 f_mo_sms_wait_rp_ack(spars);
2263
Harald Weltef640a012018-04-14 17:49:21 +02002264 f_expect_clear();
2265}
2266testcase TC_smpp_mo_sms() runs on MTC_CT {
2267 var BSC_ConnHdlr vc_conn;
2268 f_init();
2269 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2270 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2271 vc_conn.done;
2272 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2273}
2274
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002275/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2276friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2277runs on BSC_ConnHdlr {
2278 var SmsParameters spars := valueof(t_SmsPars);
2279 var SMPP_PDU smpp_pdu;
2280 timer T := 3.0;
2281
2282 f_init_handler(pars);
2283
2284 /* Perform location update */
2285 f_perform_lu();
2286
2287 /* MS/UE submits a MO SMS */
2288 f_establish_fully(EST_TYPE_MO_SMS);
2289 f_mo_sms_submit(spars);
2290
2291 /* ESME responds with an error (Invalid Destination Address) */
2292 T.start;
2293 alt {
2294 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2295 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2296 }
2297 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2298 [] T.timeout {
2299 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2300 mtc.stop;
2301 }
2302 }
2303
2304 /* Expect RP-ERROR on BSSAP interface */
2305 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2306 f_mo_sms_wait_rp_ack(spars);
2307
2308 f_expect_clear();
2309}
2310testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2311 var BSC_ConnHdlr vc_conn;
2312 f_init();
2313 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2314 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2315 vc_conn.done;
2316 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2317}
2318
Harald Weltee13cfb22019-04-23 16:52:02 +02002319
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002320/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002321friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002322runs on BSC_ConnHdlr {
2323 var SmsParameters spars := valueof(t_SmsPars);
2324 var GSUP_PDU gsup_msg_rx;
2325 var octetstring sm_tpdu;
2326
2327 f_init_handler(pars);
2328
2329 /* We need to inspect GSUP activity */
2330 f_create_gsup_expect(hex2str(g_pars.imsi));
2331
2332 /* Perform location update */
2333 f_perform_lu();
2334
2335 /* Send CM Service Request for SMS */
2336 f_establish_fully(EST_TYPE_MO_SMS);
2337
2338 /* Prepare expected SM-RP-UI (SM TPDU) */
2339 enc_TPDU_RP_DATA_MS_SGSN_fast(
2340 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2341 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2342 spars.tp.udl, spars.tp.ud)),
2343 sm_tpdu);
2344
2345 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2346 imsi := g_pars.imsi,
2347 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002348 /* SM-RP-DA: SMSC address */
2349 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2350 number := spars.rp.smsc_addr.rP_NumberDigits,
2351 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2352 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2353 ext := spars.rp.smsc_addr.rP_Ext)),
2354 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2355 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2356 number := g_pars.msisdn,
2357 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2358 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002359 /* TODO: can we use decmatch here? */
2360 sm_rp_ui := sm_tpdu
2361 );
2362
2363 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2364 f_mo_sms_submit(spars);
2365 alt {
2366 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002367 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002368 setverdict(pass);
2369 }
2370 [] GSUP.receive {
2371 log("RX unexpected GSUP message");
2372 setverdict(fail);
2373 mtc.stop;
2374 }
2375 }
2376
2377 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2378 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2379 imsi := g_pars.imsi,
2380 sm_rp_mr := spars.rp.msg_ref)));
2381 /* Expect RP-ACK on DTAP */
2382 f_mo_sms_wait_rp_ack(spars);
2383
2384 f_expect_clear();
2385}
2386testcase TC_gsup_mo_sms() runs on MTC_CT {
2387 var BSC_ConnHdlr vc_conn;
2388 f_init();
2389 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2390 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2391 vc_conn.done;
2392 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2393}
2394
Harald Weltee13cfb22019-04-23 16:52:02 +02002395
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002396/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002397friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002398runs on BSC_ConnHdlr {
2399 var SmsParameters spars := valueof(t_SmsPars);
2400 var GSUP_PDU gsup_msg_rx;
2401
2402 f_init_handler(pars);
2403
2404 /* We need to inspect GSUP activity */
2405 f_create_gsup_expect(hex2str(g_pars.imsi));
2406
2407 /* Perform location update */
2408 f_perform_lu();
2409
2410 /* Send CM Service Request for SMS */
2411 f_establish_fully(EST_TYPE_MO_SMS);
2412
2413 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2414 imsi := g_pars.imsi,
2415 sm_rp_mr := spars.rp.msg_ref,
2416 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2417 );
2418
2419 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2420 f_mo_smma(spars);
2421 alt {
2422 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002423 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002424 setverdict(pass);
2425 }
2426 [] GSUP.receive {
2427 log("RX unexpected GSUP message");
2428 setverdict(fail);
2429 mtc.stop;
2430 }
2431 }
2432
2433 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2434 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2435 imsi := g_pars.imsi,
2436 sm_rp_mr := spars.rp.msg_ref)));
2437 /* Expect RP-ACK on DTAP */
2438 f_mo_sms_wait_rp_ack(spars);
2439
2440 f_expect_clear();
2441}
2442testcase TC_gsup_mo_smma() runs on MTC_CT {
2443 var BSC_ConnHdlr vc_conn;
2444 f_init();
2445 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2446 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2447 vc_conn.done;
2448 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2449}
2450
Harald Weltee13cfb22019-04-23 16:52:02 +02002451
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002452/* Helper for sending MT SMS over GSUP */
2453private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2454runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002455 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002456 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2457 number := spars.rp.smsc_addr.rP_NumberDigits,
2458 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2459 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2460 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002461
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002462 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2463 imsi := g_pars.imsi,
2464 /* NOTE: MSC should assign RP-MR itself */
2465 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002466 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002467 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002468 /* Encoded SMS TPDU (taken from Wireshark)
2469 * FIXME: we should encode spars somehow */
2470 sm_rp_ui := '00068021436500008111328130858200'O,
2471 sm_rp_mms := mms
2472 ));
2473}
2474
2475/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002476friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002477runs on BSC_ConnHdlr {
2478 var SmsParameters spars := valueof(t_SmsPars);
2479
2480 f_init_handler(pars);
2481
2482 /* We need to inspect GSUP activity */
2483 f_create_gsup_expect(hex2str(g_pars.imsi));
2484
2485 /* Perform location update */
2486 f_perform_lu();
2487
2488 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002489 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002490
2491 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2492 imsi := g_pars.imsi,
2493 /* NOTE: MSC should assign RP-MR itself */
2494 sm_rp_mr := ?
2495 );
2496
2497 /* Submit a MT SMS on GSUP */
2498 f_gsup_forwardSM_req(spars);
2499
2500 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002501 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002502 f_establish_fully(EST_TYPE_PAG_RESP);
2503
2504 /* Wait for MT SMS on DTAP */
2505 f_mt_sms_expect(spars);
2506
2507 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2508 f_mt_sms_send_rp_ack(spars);
2509 alt {
2510 [] GSUP.receive(mt_forwardSM_res) {
2511 log("RX MT-forwardSM-Res (RP-ACK)");
2512 setverdict(pass);
2513 }
2514 [] GSUP.receive {
2515 log("RX unexpected GSUP message");
2516 setverdict(fail);
2517 mtc.stop;
2518 }
2519 }
2520
2521 f_expect_clear();
2522}
2523testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2524 var BSC_ConnHdlrPars pars;
2525 var BSC_ConnHdlr vc_conn;
2526 f_init();
2527 pars := f_init_pars(90);
2528 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2529 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2530 vc_conn.done;
2531 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2532}
2533
Harald Weltee13cfb22019-04-23 16:52:02 +02002534
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002535/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002536friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002537runs on BSC_ConnHdlr {
2538 var SmsParameters spars := valueof(t_SmsPars);
2539 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2540
2541 f_init_handler(pars);
2542
2543 /* We need to inspect GSUP activity */
2544 f_create_gsup_expect(hex2str(g_pars.imsi));
2545
2546 /* Perform location update */
2547 f_perform_lu();
2548
2549 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002550 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002551
2552 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2553 imsi := g_pars.imsi,
2554 /* NOTE: MSC should assign RP-MR itself */
2555 sm_rp_mr := ?,
2556 sm_rp_cause := sm_rp_cause
2557 );
2558
2559 /* Submit a MT SMS on GSUP */
2560 f_gsup_forwardSM_req(spars);
2561
2562 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002563 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002564 f_establish_fully(EST_TYPE_PAG_RESP);
2565
2566 /* Wait for MT SMS on DTAP */
2567 f_mt_sms_expect(spars);
2568
2569 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2570 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2571 alt {
2572 [] GSUP.receive(mt_forwardSM_err) {
2573 log("RX MT-forwardSM-Err (RP-ERROR)");
2574 setverdict(pass);
2575 mtc.stop;
2576 }
2577 [] GSUP.receive {
2578 log("RX unexpected GSUP message");
2579 setverdict(fail);
2580 mtc.stop;
2581 }
2582 }
2583
2584 f_expect_clear();
2585}
2586testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2587 var BSC_ConnHdlrPars pars;
2588 var BSC_ConnHdlr vc_conn;
2589 f_init();
2590 pars := f_init_pars(91);
2591 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2592 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2593 vc_conn.done;
2594 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2595}
2596
Harald Weltee13cfb22019-04-23 16:52:02 +02002597
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002598/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002599friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002600runs on BSC_ConnHdlr {
2601 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2602 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2603
2604 f_init_handler(pars);
2605
2606 /* We need to inspect GSUP activity */
2607 f_create_gsup_expect(hex2str(g_pars.imsi));
2608
2609 /* Perform location update */
2610 f_perform_lu();
2611
2612 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002613 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002614
2615 /* Submit the 1st MT SMS on GSUP */
2616 log("TX MT-forwardSM-Req for the 1st SMS");
2617 f_gsup_forwardSM_req(spars1);
2618
2619 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002620 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002621 f_establish_fully(EST_TYPE_PAG_RESP);
2622
2623 /* Wait for 1st MT SMS on DTAP */
2624 f_mt_sms_expect(spars1);
2625 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2626 ", SM-RP-MR is ", spars1.rp.msg_ref);
2627
2628 /* Submit the 2nd MT SMS on GSUP */
2629 log("TX MT-forwardSM-Req for the 2nd SMS");
2630 f_gsup_forwardSM_req(spars2);
2631
2632 /* Wait for 2nd MT SMS on DTAP */
2633 f_mt_sms_expect(spars2);
2634 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2635 ", SM-RP-MR is ", spars2.rp.msg_ref);
2636
2637 /* Both transaction IDs shall be different */
2638 if (spars1.tid == spars2.tid) {
2639 log("Both DTAP transaction IDs shall be different");
2640 setverdict(fail);
2641 }
2642
2643 /* Both SM-RP-MR values shall be different */
2644 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2645 log("Both SM-RP-MR values shall be different");
2646 setverdict(fail);
2647 }
2648
2649 /* Both SM-RP-MR values shall be assigned */
2650 if (spars1.rp.msg_ref == 'FF'O) {
2651 log("Unassigned SM-RP-MR value for the 1st SMS");
2652 setverdict(fail);
2653 }
2654 if (spars2.rp.msg_ref == 'FF'O) {
2655 log("Unassigned SM-RP-MR value for the 2nd SMS");
2656 setverdict(fail);
2657 }
2658
2659 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2660 f_mt_sms_send_rp_ack(spars1);
2661 alt {
2662 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2663 imsi := g_pars.imsi,
2664 sm_rp_mr := spars1.rp.msg_ref
2665 )) {
2666 log("RX MT-forwardSM-Res (RP-ACK)");
2667 setverdict(pass);
2668 }
2669 [] GSUP.receive {
2670 log("RX unexpected GSUP message");
2671 setverdict(fail);
2672 mtc.stop;
2673 }
2674 }
2675
2676 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2677 f_mt_sms_send_rp_ack(spars2);
2678 alt {
2679 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2680 imsi := g_pars.imsi,
2681 sm_rp_mr := spars2.rp.msg_ref
2682 )) {
2683 log("RX MT-forwardSM-Res (RP-ACK)");
2684 setverdict(pass);
2685 }
2686 [] GSUP.receive {
2687 log("RX unexpected GSUP message");
2688 setverdict(fail);
2689 mtc.stop;
2690 }
2691 }
2692
2693 f_expect_clear();
2694}
2695testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2696 var BSC_ConnHdlrPars pars;
2697 var BSC_ConnHdlr vc_conn;
2698 f_init();
2699 pars := f_init_pars(92);
2700 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2701 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2702 vc_conn.done;
2703 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2704}
2705
Harald Weltee13cfb22019-04-23 16:52:02 +02002706
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002707/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002708friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002709runs on BSC_ConnHdlr {
2710 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2711 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2712
2713 f_init_handler(pars);
2714
2715 /* We need to inspect GSUP activity */
2716 f_create_gsup_expect(hex2str(g_pars.imsi));
2717
2718 /* Perform location update */
2719 f_perform_lu();
2720
2721 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002722 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002723
2724 /* Send CM Service Request for MO SMMA */
2725 f_establish_fully(EST_TYPE_MO_SMS);
2726
2727 /* Submit MO SMMA on DTAP */
2728 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2729 spars_mo.rp.msg_ref := '00'O;
2730 f_mo_smma(spars_mo);
2731
2732 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2733 alt {
2734 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2735 imsi := g_pars.imsi,
2736 sm_rp_mr := spars_mo.rp.msg_ref,
2737 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2738 )) {
2739 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2740 setverdict(pass);
2741 }
2742 [] GSUP.receive {
2743 log("RX unexpected GSUP message");
2744 setverdict(fail);
2745 mtc.stop;
2746 }
2747 }
2748
2749 /* Submit MT SMS on GSUP */
2750 log("TX MT-forwardSM-Req for the MT SMS");
2751 f_gsup_forwardSM_req(spars_mt);
2752
2753 /* Wait for MT SMS on DTAP */
2754 f_mt_sms_expect(spars_mt);
2755 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2756 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2757
2758 /* Both SM-RP-MR values shall be different */
2759 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2760 log("Both SM-RP-MR values shall be different");
2761 setverdict(fail);
2762 }
2763
2764 /* SM-RP-MR value for MT SMS shall be assigned */
2765 if (spars_mt.rp.msg_ref == 'FF'O) {
2766 log("Unassigned SM-RP-MR value for the MT SMS");
2767 setverdict(fail);
2768 }
2769
2770 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2771 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2772 imsi := g_pars.imsi,
2773 sm_rp_mr := spars_mo.rp.msg_ref)));
2774 /* Expect RP-ACK for MO SMMA on DTAP */
2775 f_mo_sms_wait_rp_ack(spars_mo);
2776
2777 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2778 f_mt_sms_send_rp_ack(spars_mt);
2779 alt {
2780 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2781 imsi := g_pars.imsi,
2782 sm_rp_mr := spars_mt.rp.msg_ref
2783 )) {
2784 log("RX MT-forwardSM-Res (RP-ACK)");
2785 setverdict(pass);
2786 }
2787 [] GSUP.receive {
2788 log("RX unexpected GSUP message");
2789 setverdict(fail);
2790 mtc.stop;
2791 }
2792 }
2793
2794 f_expect_clear();
2795}
2796testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2797 var BSC_ConnHdlrPars pars;
2798 var BSC_ConnHdlr vc_conn;
2799 f_init();
2800 pars := f_init_pars(93);
2801 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2802 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2803 vc_conn.done;
2804 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2805}
2806
Harald Weltee13cfb22019-04-23 16:52:02 +02002807
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002808/* Test multi-part MT-SMS over GSUP */
2809private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2810runs on BSC_ConnHdlr {
2811 var SmsParameters spars := valueof(t_SmsPars);
2812
2813 f_init_handler(pars);
2814
2815 /* We need to inspect GSUP activity */
2816 f_create_gsup_expect(hex2str(g_pars.imsi));
2817
2818 /* Perform location update */
2819 f_perform_lu();
2820
2821 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002822 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002823
2824 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2825 imsi := g_pars.imsi,
2826 /* NOTE: MSC should assign RP-MR itself */
2827 sm_rp_mr := ?
2828 );
2829
2830 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2831 for (var integer i := 3; i >= 0; i := i-1) {
2832 /* Submit a MT SMS on GSUP (MMS is decremented) */
2833 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2834
2835 /* Expect Paging Request and Establish connection */
2836 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002837 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002838 f_establish_fully(EST_TYPE_PAG_RESP);
2839 }
2840
2841 /* Wait for MT SMS on DTAP */
2842 f_mt_sms_expect(spars);
2843
2844 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2845 f_mt_sms_send_rp_ack(spars);
2846 alt {
2847 [] GSUP.receive(mt_forwardSM_res) {
2848 log("RX MT-forwardSM-Res (RP-ACK)");
2849 setverdict(pass);
2850 }
2851 [] GSUP.receive {
2852 log("RX unexpected GSUP message");
2853 setverdict(fail);
2854 mtc.stop;
2855 }
2856 }
2857
2858 /* Keep some 'distance' between transmissions */
2859 f_sleep(1.5);
2860 }
2861
2862 f_expect_clear();
2863}
2864testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2865 var BSC_ConnHdlrPars pars;
2866 var BSC_ConnHdlr vc_conn;
2867 f_init();
2868 pars := f_init_pars(91);
2869 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2870 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2871 vc_conn.done;
2872 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2873}
2874
Harald Weltef640a012018-04-14 17:49:21 +02002875/* convert GSM L3 TON to SMPP_TON enum */
2876function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2877 select (ton) {
2878 case ('000'B) { return unknown; }
2879 case ('001'B) { return international; }
2880 case ('010'B) { return national; }
2881 case ('011'B) { return network_specific; }
2882 case ('100'B) { return subscriber_number; }
2883 case ('101'B) { return alphanumeric; }
2884 case ('110'B) { return abbreviated; }
2885 }
2886 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002887 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002888}
2889/* convert GSM L3 NPI to SMPP_NPI enum */
2890function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2891 select (npi) {
2892 case ('0000'B) { return unknown; }
2893 case ('0001'B) { return isdn; }
2894 case ('0011'B) { return data; }
2895 case ('0100'B) { return telex; }
2896 case ('0110'B) { return land_mobile; }
2897 case ('1000'B) { return national; }
2898 case ('1001'B) { return private_; }
2899 case ('1010'B) { return ermes; }
2900 }
2901 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002902 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002903}
2904
2905/* build a SMPP_SM from SmsParameters */
2906function f_mt_sm_from_spars(SmsParameters spars)
2907runs on BSC_ConnHdlr return SMPP_SM {
2908 var SMPP_SM sm := {
2909 service_type := "CMT",
2910 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2911 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2912 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2913 dest_addr_ton := international,
2914 dest_addr_npi := isdn,
2915 destination_addr := hex2str(g_pars.msisdn),
2916 esm_class := '00000001'B,
2917 protocol_id := 0,
2918 priority_flag := 0,
2919 schedule_delivery_time := "",
2920 validity_period := "",
2921 registered_delivery := '00000000'B,
2922 replace_if_present := 0,
2923 data_coding := '00000001'B,
2924 sm_default_msg_id := 0,
2925 sm_length := spars.tp.udl,
2926 short_message := spars.tp.ud,
2927 opt_pars := {}
2928 };
2929 return sm;
2930}
2931
2932/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2933private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2934 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2935 if (trans_mode) {
2936 sm.esm_class := '00000010'B;
2937 }
2938
2939 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2940 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2941 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2942 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2943 * before we expect the SMS delivery on the BSC/radio side */
2944 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2945 }
2946
2947 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002948 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002949 /* Establish DTAP / BSSAP / SCCP connection */
2950 f_establish_fully(EST_TYPE_PAG_RESP);
2951 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2952
2953 f_mt_sms(spars);
2954
2955 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2956 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2957 }
2958 f_expect_clear();
2959}
2960
2961/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2962private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2963 f_init_handler(pars);
2964
2965 /* Perform location update so IMSI is known + registered in MSC/VLR */
2966 f_perform_lu();
2967 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2968
2969 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002970 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002971
2972 var SmsParameters spars := valueof(t_SmsPars);
2973 /* TODO: test with more intelligent user data; test different coding schemes */
2974 spars.tp.ud := '00'O;
2975 spars.tp.udl := 1;
2976
2977 /* first test the non-transaction store+forward mode */
2978 f_smpp_mt_sms(spars, false);
2979
2980 /* then test the transaction mode */
2981 f_smpp_mt_sms(spars, true);
2982}
2983testcase TC_smpp_mt_sms() runs on MTC_CT {
2984 var BSC_ConnHdlr vc_conn;
2985 f_init();
2986 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2987 vc_conn.done;
2988}
2989
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002990/***********************************************************************
2991 * USSD Testing
2992 ***********************************************************************/
2993
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002994private altstep as_unexp_gsup_or_bssap_msg()
2995runs on BSC_ConnHdlr {
2996 [] GSUP.receive {
2997 setverdict(fail, "Unknown/unexpected GSUP received");
2998 self.stop;
2999 }
3000 [] BSSAP.receive {
3001 setverdict(fail, "Unknown/unexpected BSSAP message received");
3002 self.stop;
3003 }
3004}
3005
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003006private function f_expect_gsup_msg(template GSUP_PDU msg,
3007 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003008runs on BSC_ConnHdlr return GSUP_PDU {
3009 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003010 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003011
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003012 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003013 alt {
3014 [] GSUP.receive(msg) -> value gsup_msg_complete {
3015 setverdict(pass);
3016 }
3017 /* We don't expect anything else */
3018 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003019 [] T.timeout {
3020 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3021 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003022 }
3023
3024 return gsup_msg_complete;
3025}
3026
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003027private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3028 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003029runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3030 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003031 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003032
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003033 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003034 alt {
3035 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3036 setverdict(pass);
3037 }
3038 /* We don't expect anything else */
3039 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003040 [] T.timeout {
3041 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3042 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003043 }
3044
3045 return bssap_msg_complete.dtap;
3046}
3047
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003048/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003049friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003050runs on BSC_ConnHdlr {
3051 f_init_handler(pars);
3052
3053 /* Perform location update */
3054 f_perform_lu();
3055
3056 /* Send CM Service Request for SS/USSD */
3057 f_establish_fully(EST_TYPE_SS_ACT);
3058
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003059 /* We need to inspect GSUP activity */
3060 f_create_gsup_expect(hex2str(g_pars.imsi));
3061
3062 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3063 invoke_id := 5, /* Phone may not start from 0 or 1 */
3064 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3065 ussd_string := "*#100#"
3066 );
3067
3068 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3069 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3070 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3071 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3072 )
3073
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003074 /* Compose a new SS/REGISTER message with request */
3075 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3076 tid := 1, /* We just need a single transaction */
3077 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003078 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003079 );
3080
3081 /* Compose SS/RELEASE_COMPLETE template with expected response */
3082 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3083 tid := 1, /* Response should arrive within the same transaction */
3084 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003085 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003086 );
3087
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003088 /* Compose expected MSC -> HLR message */
3089 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3090 imsi := g_pars.imsi,
3091 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3092 ss := valueof(facility_req)
3093 );
3094
3095 /* To be used for sending response with correct session ID */
3096 var GSUP_PDU gsup_req_complete;
3097
3098 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003099 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003100 /* Expect GSUP message containing the SS payload */
3101 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3102
3103 /* Compose the response from HLR using received session ID */
3104 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3105 imsi := g_pars.imsi,
3106 sid := gsup_req_complete.ies[1].val.session_id,
3107 state := OSMO_GSUP_SESSION_STATE_END,
3108 ss := valueof(facility_rsp)
3109 );
3110
3111 /* Finally, HLR terminates the session */
3112 GSUP.send(gsup_rsp);
3113 /* Expect RELEASE_COMPLETE message with the response */
3114 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003115
3116 f_expect_clear();
3117}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003118testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003119 var BSC_ConnHdlr vc_conn;
3120 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003121 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003122 vc_conn.done;
3123}
3124
Harald Weltee13cfb22019-04-23 16:52:02 +02003125
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003126/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003127friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003128runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003129 timer T := 5.0;
3130
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003131 f_init_handler(pars);
3132
3133 /* Perform location update */
3134 f_perform_lu();
3135
Harald Welte6811d102019-04-14 22:23:14 +02003136 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003137
3138 /* We need to inspect GSUP activity */
3139 f_create_gsup_expect(hex2str(g_pars.imsi));
3140
3141 /* Facility IE with network-originated USSD notification */
3142 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3143 op_code := SS_OP_CODE_USS_NOTIFY,
3144 ussd_string := "Mahlzeit!"
3145 );
3146
3147 /* Facility IE with acknowledgment to the USSD notification */
3148 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3149 /* In case of USSD notification, Return Result is empty */
3150 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3151 );
3152
3153 /* Compose a new MT SS/REGISTER message with USSD notification */
3154 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3155 tid := 0, /* FIXME: most likely, it should be 0 */
3156 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3157 facility := valueof(facility_req)
3158 );
3159
3160 /* Compose HLR -> MSC GSUP message */
3161 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3162 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003163 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003164 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3165 ss := valueof(facility_req)
3166 );
3167
3168 /* Send it to MSC and expect Paging Request */
3169 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003170 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003171 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003172 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3173 setverdict(pass);
3174 }
Harald Welte62113fc2019-05-09 13:04:02 +02003175 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003176 setverdict(pass);
3177 }
3178 /* We don't expect anything else */
3179 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003180 [] T.timeout {
3181 setverdict(fail, "Timeout waiting for Paging Request");
3182 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003183 }
3184
3185 /* Send Paging Response and expect USSD notification */
3186 f_establish_fully(EST_TYPE_PAG_RESP);
3187 /* Expect MT REGISTER message with USSD notification */
3188 f_expect_mt_dtap_msg(ussd_ntf);
3189
3190 /* Compose a new MO SS/FACILITY message with empty response */
3191 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3192 tid := 0, /* FIXME: it shall match the request tid */
3193 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3194 facility := valueof(facility_rsp)
3195 );
3196
3197 /* Compose expected MSC -> HLR GSUP message */
3198 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3199 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003200 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003201 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3202 ss := valueof(facility_rsp)
3203 );
3204
3205 /* MS sends response to the notification */
3206 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3207 /* Expect GSUP message containing the SS payload */
3208 f_expect_gsup_msg(gsup_rsp);
3209
3210 /* Compose expected MT SS/RELEASE COMPLETE message */
3211 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3212 tid := 0, /* FIXME: it shall match the request tid */
3213 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3214 facility := omit
3215 );
3216
3217 /* Compose MSC -> HLR GSUP message */
3218 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3219 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003220 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003221 state := OSMO_GSUP_SESSION_STATE_END
3222 );
3223
3224 /* Finally, HLR terminates the session */
3225 GSUP.send(gsup_term)
3226 /* Expect MT RELEASE COMPLETE without Facility IE */
3227 f_expect_mt_dtap_msg(ussd_term);
3228
3229 f_expect_clear();
3230}
3231testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3232 var BSC_ConnHdlr vc_conn;
3233 f_init();
3234 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3235 vc_conn.done;
3236}
3237
Harald Weltee13cfb22019-04-23 16:52:02 +02003238
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003239/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003240friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003241runs on BSC_ConnHdlr {
3242 f_init_handler(pars);
3243
3244 /* Call parameters taken from f_tc_lu_and_mt_call */
3245 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003246
3247 /* Perform location update */
3248 f_perform_lu();
3249
3250 /* Establish a MT call */
3251 f_mt_call_establish(cpars);
3252
3253 /* Hold the call for some time */
3254 f_sleep(1.0);
3255
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003256 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3257 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3258 ussd_string := "*#100#"
3259 );
3260
3261 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3262 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3263 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3264 )
3265
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003266 /* Compose a new SS/REGISTER message with request */
3267 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3268 tid := 1, /* We just need a single transaction */
3269 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003270 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003271 );
3272
3273 /* Compose SS/RELEASE_COMPLETE template with expected response */
3274 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3275 tid := 1, /* Response should arrive within the same transaction */
3276 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003277 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003278 );
3279
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003280 /* Compose expected MSC -> HLR message */
3281 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3282 imsi := g_pars.imsi,
3283 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3284 ss := valueof(facility_req)
3285 );
3286
3287 /* To be used for sending response with correct session ID */
3288 var GSUP_PDU gsup_req_complete;
3289
3290 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003291 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003292 /* Expect GSUP message containing the SS payload */
3293 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3294
3295 /* Compose the response from HLR using received session ID */
3296 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3297 imsi := g_pars.imsi,
3298 sid := gsup_req_complete.ies[1].val.session_id,
3299 state := OSMO_GSUP_SESSION_STATE_END,
3300 ss := valueof(facility_rsp)
3301 );
3302
3303 /* Finally, HLR terminates the session */
3304 GSUP.send(gsup_rsp);
3305 /* Expect RELEASE_COMPLETE message with the response */
3306 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003307
3308 /* Hold the call for some time */
3309 f_sleep(1.0);
3310
3311 /* Release the call (does Clear Complete itself) */
3312 f_call_hangup(cpars, true);
3313}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003314testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003315 var BSC_ConnHdlr vc_conn;
3316 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003317 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003318 vc_conn.done;
3319}
3320
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003321/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003322friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003323 f_init_handler(pars);
3324 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003325 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003326
3327 f_perform_lu();
3328
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003329 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003330 f_mo_call_establish(cpars);
3331 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003332 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003333
3334 f_sleep(1.0);
3335}
3336testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3337 var BSC_ConnHdlr vc_conn;
3338 f_init();
3339
3340 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3341 vc_conn.done;
3342}
3343
Harald Weltee13cfb22019-04-23 16:52:02 +02003344
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003345/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003346friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003347runs on BSC_ConnHdlr {
3348 f_init_handler(pars);
3349
3350 /* Call parameters taken from f_tc_lu_and_mt_call */
3351 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003352
3353 /* Perform location update */
3354 f_perform_lu();
3355
3356 /* Establish a MT call */
3357 f_mt_call_establish(cpars);
3358
3359 /* Hold the call for some time */
3360 f_sleep(1.0);
3361
3362 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3363 op_code := SS_OP_CODE_USS_REQUEST,
3364 ussd_string := "Please type anything..."
3365 );
3366
3367 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3368 op_code := SS_OP_CODE_USS_REQUEST,
3369 ussd_string := "Nope."
3370 )
3371
3372 /* Compose MT SS/REGISTER message with network-originated request */
3373 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3374 tid := 0, /* FIXME: most likely, it should be 0 */
3375 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3376 facility := valueof(facility_req)
3377 );
3378
3379 /* Compose HLR -> MSC GSUP message */
3380 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3381 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003382 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003383 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3384 ss := valueof(facility_req)
3385 );
3386
3387 /* Send it to MSC */
3388 GSUP.send(gsup_req);
3389 /* Expect MT REGISTER message with USSD request */
3390 f_expect_mt_dtap_msg(ussd_req);
3391
3392 /* Compose a new MO SS/FACILITY message with response */
3393 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3394 tid := 0, /* FIXME: it shall match the request tid */
3395 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3396 facility := valueof(facility_rsp)
3397 );
3398
3399 /* Compose expected MSC -> HLR GSUP message */
3400 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3401 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003402 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003403 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3404 ss := valueof(facility_rsp)
3405 );
3406
3407 /* MS sends response */
3408 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3409 f_expect_gsup_msg(gsup_rsp);
3410
3411 /* Compose expected MT SS/RELEASE COMPLETE message */
3412 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3413 tid := 0, /* FIXME: it shall match the request tid */
3414 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3415 facility := omit
3416 );
3417
3418 /* Compose MSC -> HLR GSUP message */
3419 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3420 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003421 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003422 state := OSMO_GSUP_SESSION_STATE_END
3423 );
3424
3425 /* Finally, HLR terminates the session */
3426 GSUP.send(gsup_term);
3427 /* Expect MT RELEASE COMPLETE without Facility IE */
3428 f_expect_mt_dtap_msg(ussd_term);
3429
3430 /* Hold the call for some time */
3431 f_sleep(1.0);
3432
3433 /* Release the call (does Clear Complete itself) */
3434 f_call_hangup(cpars, true);
3435}
3436testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3437 var BSC_ConnHdlr vc_conn;
3438 f_init();
3439 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3440 vc_conn.done;
3441}
3442
Harald Weltee13cfb22019-04-23 16:52:02 +02003443
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003444/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003445friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003446runs on BSC_ConnHdlr {
3447 f_init_handler(pars);
3448
3449 /* Perform location update */
3450 f_perform_lu();
3451
3452 /* Send CM Service Request for SS/USSD */
3453 f_establish_fully(EST_TYPE_SS_ACT);
3454
3455 /* We need to inspect GSUP activity */
3456 f_create_gsup_expect(hex2str(g_pars.imsi));
3457
3458 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3459 invoke_id := 1, /* Initial request */
3460 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3461 ussd_string := "*6766*266#"
3462 );
3463
3464 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3465 invoke_id := 2, /* Counter request */
3466 op_code := SS_OP_CODE_USS_REQUEST,
3467 ussd_string := "Password?!?"
3468 )
3469
3470 /* Compose MO SS/REGISTER message with request */
3471 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3472 tid := 1, /* We just need a single transaction */
3473 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3474 facility := valueof(facility_ms_req)
3475 );
3476
3477 /* Compose expected MSC -> HLR message */
3478 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3479 imsi := g_pars.imsi,
3480 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3481 ss := valueof(facility_ms_req)
3482 );
3483
3484 /* To be used for sending response with correct session ID */
3485 var GSUP_PDU gsup_ms_req_complete;
3486
3487 /* Initiate a new transaction */
3488 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3489 /* Expect GSUP request with original Facility IE */
3490 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3491
3492 /* Compose the response from HLR using received session ID */
3493 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3494 imsi := g_pars.imsi,
3495 sid := gsup_ms_req_complete.ies[1].val.session_id,
3496 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3497 ss := valueof(facility_net_req)
3498 );
3499
3500 /* Compose expected MT SS/FACILITY template with counter request */
3501 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3502 tid := 1, /* Response should arrive within the same transaction */
3503 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3504 facility := valueof(facility_net_req)
3505 );
3506
3507 /* Send response over GSUP */
3508 GSUP.send(gsup_net_req);
3509 /* Expect MT SS/FACILITY message with counter request */
3510 f_expect_mt_dtap_msg(ussd_net_req);
3511
3512 /* Compose MO SS/RELEASE COMPLETE */
3513 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3514 tid := 1, /* Response should arrive within the same transaction */
3515 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3516 facility := omit
3517 /* TODO: cause? */
3518 );
3519
3520 /* Compose expected HLR -> MSC abort message */
3521 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3522 imsi := g_pars.imsi,
3523 sid := gsup_ms_req_complete.ies[1].val.session_id,
3524 state := OSMO_GSUP_SESSION_STATE_END
3525 );
3526
3527 /* Abort transaction */
3528 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3529 /* Expect GSUP message indicating abort */
3530 f_expect_gsup_msg(gsup_abort);
3531
3532 f_expect_clear();
3533}
3534testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3535 var BSC_ConnHdlr vc_conn;
3536 f_init();
3537 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3538 vc_conn.done;
3539}
3540
Harald Weltee13cfb22019-04-23 16:52:02 +02003541
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003542/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003543friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003544runs on BSC_ConnHdlr {
3545 f_init_handler(pars);
3546
3547 /* Perform location update */
3548 f_perform_lu();
3549
3550 /* Send CM Service Request for SS/USSD */
3551 f_establish_fully(EST_TYPE_SS_ACT);
3552
3553 /* We need to inspect GSUP activity */
3554 f_create_gsup_expect(hex2str(g_pars.imsi));
3555
3556 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3557 invoke_id := 1,
3558 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3559 ussd_string := "#release_me");
3560
3561 /* Compose MO SS/REGISTER message with request */
3562 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3563 tid := 1, /* An arbitrary transaction identifier */
3564 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3565 facility := valueof(facility_ms_req));
3566
3567 /* Compose expected MSC -> HLR message */
3568 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3569 imsi := g_pars.imsi,
3570 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3571 ss := valueof(facility_ms_req));
3572
3573 /* To be used for sending response with correct session ID */
3574 var GSUP_PDU gsup_ms_req_complete;
3575
3576 /* Initiate a new SS transaction */
3577 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3578 /* Expect GSUP request with original Facility IE */
3579 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3580
3581 /* Don't respond, wait for timeout */
3582 f_sleep(3.0);
3583
3584 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3585 tid := 1, /* Should match the request's tid */
3586 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3587 cause := *, /* TODO: expect some specific value */
3588 facility := omit);
3589
3590 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3591 imsi := g_pars.imsi,
3592 sid := gsup_ms_req_complete.ies[1].val.session_id,
3593 state := OSMO_GSUP_SESSION_STATE_END,
3594 cause := ?); /* TODO: expect some specific value */
3595
3596 /* Expect release on both interfaces */
3597 interleave {
3598 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3599 [] GSUP.receive(gsup_rel) { };
3600 }
3601
3602 f_expect_clear();
3603 setverdict(pass);
3604}
3605testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3606 var BSC_ConnHdlr vc_conn;
3607 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003608 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003609 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3610 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003611 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003612}
3613
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003614/* MT (network-originated) USSD for unknown subscriber */
3615friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3616runs on BSC_ConnHdlr {
3617 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3618 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003619
3620 f_init_handler(pars);
3621 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3622 f_create_gsup_expect(hex2str(imsi));
3623
3624 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3625 imsi := imsi,
3626 sid := sid,
3627 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3628 ss := f_rnd_octstring(23)
3629 );
3630
3631 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3632 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3633 imsi := imsi,
3634 sid := sid,
3635 state := OSMO_GSUP_SESSION_STATE_END,
3636 cause := 2 /* FIXME: introduce an enumerated type! */
3637 );
3638
3639 /* Initiate a MT USSD notification */
3640 GSUP.send(gsup_req);
3641
3642 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003643 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003644}
3645testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3646 var BSC_ConnHdlr vc_conn;
3647 f_init();
3648 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3649 vc_conn.done;
3650}
3651
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003652/* MO (mobile-originated) SS/USSD for unknown transaction */
3653friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3654runs on BSC_ConnHdlr {
3655 f_init_handler(pars);
3656
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003657 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003658 f_create_gsup_expect(hex2str(g_pars.imsi));
3659
3660 /* Perform location update */
3661 f_perform_lu();
3662
3663 /* Send CM Service Request for SS/USSD */
3664 f_establish_fully(EST_TYPE_SS_ACT);
3665
3666 /* GSM 04.80 FACILITY message for a non-existing transaction */
3667 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3668 tid := 1, /* An arbitrary transaction identifier */
3669 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3670 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3671 );
3672
3673 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3674 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3675 tid := 1, /* An arbitrary transaction identifier */
3676 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3677 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3678 );
3679
3680 /* Expected response from the network */
3681 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3682 tid := 1, /* Same as in the FACILITY message */
3683 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3684 facility := omit
3685 );
3686
3687 /* Send GSM 04.80 FACILITY for non-existing transaction */
3688 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3689
3690 /* Expect GSM 04.80 RELEASE COMPLETE message */
3691 f_expect_mt_dtap_msg(mt_ss_rel);
3692 f_expect_clear();
3693
3694 /* Send another CM Service Request for SS/USSD */
3695 f_establish_fully(EST_TYPE_SS_ACT);
3696
3697 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3698 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3699
3700 /* Expect GSM 04.80 RELEASE COMPLETE message */
3701 f_expect_mt_dtap_msg(mt_ss_rel);
3702 f_expect_clear();
3703}
3704testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3705 var BSC_ConnHdlr vc_conn;
3706 f_init();
3707 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3708 vc_conn.done;
3709}
3710
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003711/* MT (network-originated) USSD for unknown session */
3712friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3713runs on BSC_ConnHdlr {
3714 var OCT4 sid := '20000333'O;
3715
3716 f_init_handler(pars);
3717
3718 /* Perform location update */
3719 f_perform_lu();
3720
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003721 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003722 f_create_gsup_expect(hex2str(g_pars.imsi));
3723
3724 /* Request referencing a non-existing SS session */
3725 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3726 imsi := g_pars.imsi,
3727 sid := sid,
3728 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3729 ss := f_rnd_octstring(23)
3730 );
3731
3732 /* Error with some cause value */
3733 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3734 imsi := g_pars.imsi,
3735 sid := sid,
3736 state := OSMO_GSUP_SESSION_STATE_END,
3737 cause := ? /* FIXME: introduce an enumerated type! */
3738 );
3739
3740 /* Initiate a MT USSD notification */
3741 GSUP.send(gsup_req);
3742
3743 /* Expect GSUP PROC_SS_ERROR message */
3744 f_expect_gsup_msg(gsup_rsp);
3745}
3746testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3747 var BSC_ConnHdlr vc_conn;
3748 f_init();
3749 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3750 vc_conn.done;
3751}
3752
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003753/* MT (network-originated) USSD and no response to Paging Request */
3754friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3755runs on BSC_ConnHdlr {
3756 timer TP := 2.0; /* Paging timer */
3757
3758 f_init_handler(pars);
3759
3760 /* Perform location update */
3761 f_perform_lu();
3762
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003763 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003764 f_create_gsup_expect(hex2str(g_pars.imsi));
3765
3766 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3767 imsi := g_pars.imsi,
3768 sid := '20000444'O,
3769 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3770 ss := f_rnd_octstring(23)
3771 );
3772
3773 /* Error with some cause value */
3774 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3775 imsi := g_pars.imsi,
3776 sid := '20000444'O,
3777 state := OSMO_GSUP_SESSION_STATE_END,
3778 cause := ? /* FIXME: introduce an enumerated type! */
3779 );
3780
3781 /* Initiate a MT USSD notification */
3782 GSUP.send(gsup_req);
3783
3784 /* Send it to MSC and expect Paging Request */
3785 TP.start;
3786 alt {
3787 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3788 setverdict(pass);
3789 }
3790 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3791 setverdict(pass);
3792 }
3793 /* We don't expect anything else */
3794 [] as_unexp_gsup_or_bssap_msg();
3795 [] TP.timeout {
3796 setverdict(fail, "Timeout waiting for Paging Request");
3797 }
3798 }
3799
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07003800 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
3801 * OsmoMSC waits for Paging Response 10 seconds by default. */
3802 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003803}
3804testcase TC_proc_ss_paging_fail() runs on MTC_CT {
3805 var BSC_ConnHdlr vc_conn;
3806 f_init();
3807 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
3808 vc_conn.done;
3809}
3810
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003811/* MT (network-originated) USSD followed by immediate abort */
3812friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
3813runs on BSC_ConnHdlr {
3814 var octetstring facility := f_rnd_octstring(23);
3815 var OCT4 sid := '20000555'O;
3816 timer TP := 2.0;
3817
3818 f_init_handler(pars);
3819
3820 /* Perform location update */
3821 f_perform_lu();
3822
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003823 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003824 f_create_gsup_expect(hex2str(g_pars.imsi));
3825
3826 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
3827 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3828 imsi := g_pars.imsi, sid := sid,
3829 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3830 ss := facility
3831 );
3832
3833 /* On the MS side, we expect GSM 04.80 REGISTER message */
3834 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
3835 tid := 0, /* Most likely, it should be 0 */
3836 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3837 facility := facility
3838 );
3839
3840 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
3841 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
3842 imsi := g_pars.imsi, sid := sid,
3843 state := OSMO_GSUP_SESSION_STATE_END,
3844 cause := 0 /* FIXME: introduce an enumerated type! */
3845 );
3846
3847 /* On the MS side, we expect GSM 04.80 REGISTER message */
3848 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3849 tid := 0, /* Most likely, it should be 0 */
3850 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3851 cause := *, /* FIXME: expect some specific cause value */
3852 facility := omit
3853 );
3854
3855 /* Initiate a MT USSD with random payload */
3856 GSUP.send(gsup_req);
3857
3858 /* Expect Paging Request */
3859 TP.start;
3860 alt {
3861 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3862 setverdict(pass);
3863 }
3864 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3865 setverdict(pass);
3866 }
3867 /* We don't expect anything else */
3868 [] as_unexp_gsup_or_bssap_msg();
3869 [] TP.timeout {
3870 setverdict(fail, "Timeout waiting for Paging Request");
3871 }
3872 }
3873
3874 /* Send Paging Response and establish connection */
3875 f_establish_fully(EST_TYPE_PAG_RESP);
3876 /* Expect MT REGISTER message with random facility */
3877 f_expect_mt_dtap_msg(dtap_reg);
3878
3879 /* HLR/EUSE decides to abort the session even
3880 * before getting any response from the MS */
3881 /* Initiate a MT USSD with random payload */
3882 GSUP.send(gsup_abort);
3883
3884 /* Expect RELEASE COMPLETE on ths MS side */
3885 f_expect_mt_dtap_msg(dtap_rel);
3886
3887 f_expect_clear();
3888}
3889testcase TC_proc_ss_abort() runs on MTC_CT {
3890 var BSC_ConnHdlr vc_conn;
3891 f_init();
3892 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
3893 vc_conn.done;
3894}
3895
Harald Weltee13cfb22019-04-23 16:52:02 +02003896
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01003897/* Verify multiple concurrent MO SS/USSD transactions
3898 * (one subscriber - one transaction) */
3899testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
3900 var BSC_ConnHdlr vc_conn[16];
3901 var integer i;
3902
3903 f_init();
3904
3905 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3906 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
3907 }
3908
3909 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3910 vc_conn[i].done;
3911 }
3912}
3913
3914/* Verify multiple concurrent MT SS/USSD transactions
3915 * (one subscriber - one transaction) */
3916testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
3917 var BSC_ConnHdlr vc_conn[16];
3918 var integer i;
3919 var OCT4 sid;
3920
3921 f_init();
3922
3923 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3924 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
3925 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
3926 f_init_pars(226 + i, gsup_sid := sid));
3927 }
3928
3929 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3930 vc_conn[i].done;
3931 }
3932}
3933
3934
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003935/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3936private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3937 pars.net.expect_auth := true;
3938 pars.net.expect_ciph := true;
3939 pars.net.kc_support := '02'O; /* A5/1 only */
3940 f_init_handler(pars);
3941
3942 g_pars.vec := f_gen_auth_vec_2g();
3943
3944 /* Can't use f_perform_lu() directly. Code below is based on it. */
3945
3946 /* tell GSUP dispatcher to send this IMSI to us */
3947 f_create_gsup_expect(hex2str(g_pars.imsi));
3948
3949 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3950 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003951 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003952
3953 f_mm_auth();
3954
3955 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3956 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3957 alt {
3958 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3959 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3960 }
3961 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3962 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3963 mtc.stop;
3964 }
3965 [] BSSAP.receive {
3966 setverdict(fail, "Unknown/unexpected BSSAP received");
3967 mtc.stop;
3968 }
3969 }
3970
3971 /* Expect LU reject from MSC. */
3972 alt {
3973 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3974 setverdict(pass);
3975 }
3976 [] BSSAP.receive {
3977 setverdict(fail, "Unknown/unexpected BSSAP received");
3978 mtc.stop;
3979 }
3980 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003981 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003982}
3983
3984testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3985 var BSC_ConnHdlr vc_conn;
3986 f_init();
3987 f_vty_config(MSCVTY, "network", "encryption a5 1");
3988
3989 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3990 vc_conn.done;
3991}
3992
Harald Welteb2284bd2019-05-10 11:30:43 +02003993/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
3994friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3995 f_init_handler(pars);
3996
3997 /* tell GSUP dispatcher to send this IMSI to us */
3998 f_create_gsup_expect(hex2str(g_pars.imsi));
3999
4000 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4001 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4002
4003 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4004 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4005 f_cl3_or_initial_ue(l3_lu);
4006
4007 /* Expect LU reject from MSC. */
4008 alt {
4009 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4010 setverdict(pass);
4011 }
4012 [] BSSAP.receive {
4013 setverdict(fail, "Unknown/unexpected BSSAP received");
4014 mtc.stop;
4015 }
4016 }
4017 f_expect_clear();
4018}
4019testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4020 var BSC_ConnHdlr vc_conn;
4021 f_init();
4022 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4023 vc_conn.done;
4024}
4025
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004026private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4027 pars.net.expect_auth := true;
4028 pars.net.expect_ciph := true;
4029 pars.net.kc_support := kc_support;
4030 f_init_handler(pars);
4031
4032 g_pars.vec := f_gen_auth_vec_2g();
4033
4034 /* Can't use f_perform_lu() directly. Code below is based on it. */
4035
4036 /* tell GSUP dispatcher to send this IMSI to us */
4037 f_create_gsup_expect(hex2str(g_pars.imsi));
4038
4039 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4040 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4041 f_cl3_or_initial_ue(l3_lu);
4042
4043 f_mm_auth();
4044
4045 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4046 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4047 alt {
4048 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4049 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4050 }
4051 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4052 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4053 repeat;
4054 }
4055 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4056 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4057 mtc.stop;
4058 }
4059 [] BSSAP.receive {
4060 setverdict(fail, "Unknown/unexpected BSSAP received");
4061 mtc.stop;
4062 }
4063 }
4064
4065 /* TODO: Verify MSC is using the best cipher available! How? */
4066
4067 f_msc_lu_hlr();
4068 f_accept_reject_lu();
4069 f_expect_clear();
4070 setverdict(pass);
4071}
4072
4073/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4074private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4075 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4076}
4077
4078/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4079private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4080 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4081}
4082
4083/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4084private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4085 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4086}
4087
4088testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4089 var BSC_ConnHdlr vc_conn;
4090 f_init();
4091 f_vty_config(MSCVTY, "network", "encryption a5 1");
4092
4093 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4094 vc_conn.done;
4095}
4096
4097testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4098 var BSC_ConnHdlr vc_conn;
4099 f_init();
4100 f_vty_config(MSCVTY, "network", "encryption a5 3");
4101
4102 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4103 vc_conn.done;
4104}
4105
4106testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4107 var BSC_ConnHdlr vc_conn;
4108 f_init();
4109 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4110
4111 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4112 vc_conn.done;
4113}
Harald Welteb2284bd2019-05-10 11:30:43 +02004114
Harald Weltef640a012018-04-14 17:49:21 +02004115/* TODO (SMS):
4116 * different user data lengths
4117 * SMPP transaction mode with unsuccessful delivery
4118 * queued MT-SMS with no paging response + later delivery
4119 * different data coding schemes
4120 * multi-part SMS
4121 * user-data headers
4122 * TP-PID for SMS to SIM
4123 * behavior if SMS memory is full + RP-SMMA
4124 * delivery reports
4125 * SMPP osmocom extensions
4126 * more-messages-to-send
4127 * SMS during ongoing call (SACCH/SAPI3)
4128 */
4129
4130/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004131 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4132 * malformed messages (missing IE, invalid message type): properly rejected?
4133 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4134 * 3G/2G auth permutations
4135 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004136 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004137 * too long L3 INFO in DTAP
4138 * too long / padded BSSAP
4139 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004140 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004141
Harald Weltee13cfb22019-04-23 16:52:02 +02004142/***********************************************************************
4143 * SGsAP Testing
4144 ***********************************************************************/
4145
Philipp Maier948747b2019-04-02 15:22:33 +02004146/* Check if a subscriber exists in the VLR */
4147private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4148
4149 var CtrlValue active_subsribers;
4150 var integer rc;
4151 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4152
4153 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4154 if (rc < 0) {
4155 return false;
4156 }
4157
4158 return true;
4159}
4160
Harald Welte4263c522018-12-06 11:56:27 +01004161/* Perform a location updatye at the A-Interface and run some checks to confirm
4162 * that everything is back to normal. */
4163private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4164 var SmsParameters spars := valueof(t_SmsPars);
4165
4166 /* Perform a location update, the SGs association is expected to fall
4167 * back to NULL */
4168 f_perform_lu();
4169 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4170
4171 /* Trigger a paging request and expect the paging on BSSMAP, this is
4172 * to make sure that pagings are sent throught the A-Interface again
4173 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004174 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004175 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4176
4177 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004178 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4179 setverdict(pass);
4180 }
Harald Welte62113fc2019-05-09 13:04:02 +02004181 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004182 setverdict(pass);
4183 }
4184 [] SGsAP.receive {
4185 setverdict(fail, "Received unexpected message on SGs");
4186 }
4187 }
4188
4189 /* Send an SMS to make sure that also payload messages are routed
4190 * throught the A-Interface again */
4191 f_establish_fully(EST_TYPE_MO_SMS);
4192 f_mo_sms(spars);
4193 f_expect_clear();
4194}
4195
4196private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4197 var charstring vlr_name;
4198 f_init_handler(pars);
4199
4200 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4201 log("VLR name: ", vlr_name);
4202 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004203 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004204}
4205
4206testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004207 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004208 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004209 f_init(1, true);
4210 pars := f_init_pars(11810, true);
4211 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004212 vc_conn.done;
4213}
4214
4215/* like f_mm_auth() but for SGs */
4216function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4217 if (g_pars.net.expect_auth) {
4218 g_pars.vec := f_gen_auth_vec_3g();
4219 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4220 g_pars.vec.sres,
4221 g_pars.vec.kc,
4222 g_pars.vec.ik,
4223 g_pars.vec.ck,
4224 g_pars.vec.autn,
4225 g_pars.vec.res));
4226 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4227 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4228 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4229 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4230 }
4231}
4232
4233/* like f_perform_lu(), but on SGs rather than BSSAP */
4234function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4235 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4236 var PDU_SGsAP lur;
4237 var PDU_SGsAP lua;
4238 var PDU_SGsAP mm_info;
4239 var octetstring mm_info_dtap;
4240
4241 /* tell GSUP dispatcher to send this IMSI to us */
4242 f_create_gsup_expect(hex2str(g_pars.imsi));
4243
4244 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4245 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4246 /* Old LAI, if MS sends it */
4247 /* TMSI status, if MS has no valid TMSI */
4248 /* IMEISV, if it supports "automatic device detection" */
4249 /* TAI, if available in MME */
4250 /* E-CGI, if available in MME */
4251 SGsAP.send(lur);
4252
4253 /* FIXME: is this really done over SGs? The Ue is already authenticated
4254 * via the MME ... */
4255 f_mm_auth_sgs();
4256
4257 /* Expect MSC to perform LU with HLR */
4258 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4259 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4260 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4261 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4262
4263 alt {
4264 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4265 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4266 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4267 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4268 }
4269 setverdict(pass);
4270 }
4271 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4272 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4273 }
4274 [] SGsAP.receive {
4275 setverdict(fail, "Received unexpected message on SGs");
4276 }
4277 }
4278
4279 /* Check MM information */
4280 if (mp_mm_info == true) {
4281 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4282 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4283 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4284 setverdict(fail, "Unexpected MM Information");
4285 }
4286 }
4287
4288 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4289}
4290
4291private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4292 f_init_handler(pars);
4293 f_sgs_perform_lu();
4294 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4295
4296 f_sgsap_bssmap_screening();
4297
4298 setverdict(pass);
4299}
4300testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004301 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004302 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004303 f_init(1, true);
4304 pars := f_init_pars(11811, true);
4305 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004306 vc_conn.done;
4307}
4308
4309/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4310private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4311 f_init_handler(pars);
4312 var PDU_SGsAP lur;
4313
4314 f_create_gsup_expect(hex2str(g_pars.imsi));
4315 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4316 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4317 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4318 SGsAP.send(lur);
4319
4320 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4321 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4322 alt {
4323 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4324 setverdict(pass);
4325 }
4326 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4327 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4328 mtc.stop;
4329 }
4330 [] SGsAP.receive {
4331 setverdict(fail, "Received unexpected message on SGs");
4332 }
4333 }
4334
4335 f_sgsap_bssmap_screening();
4336
4337 setverdict(pass);
4338}
4339testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004340 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004341 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004342 f_init(1, true);
4343 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004344
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004345 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004346 vc_conn.done;
4347}
4348
4349/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4350private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4351 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4352 var PDU_SGsAP lur;
4353
4354 f_init_handler(pars);
4355
4356 /* tell GSUP dispatcher to send this IMSI to us */
4357 f_create_gsup_expect(hex2str(g_pars.imsi));
4358
4359 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4360 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4361 /* Old LAI, if MS sends it */
4362 /* TMSI status, if MS has no valid TMSI */
4363 /* IMEISV, if it supports "automatic device detection" */
4364 /* TAI, if available in MME */
4365 /* E-CGI, if available in MME */
4366 SGsAP.send(lur);
4367
4368 /* FIXME: is this really done over SGs? The Ue is already authenticated
4369 * via the MME ... */
4370 f_mm_auth_sgs();
4371
4372 /* Expect MSC to perform LU with HLR */
4373 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4374 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4375 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4376 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4377
4378 alt {
4379 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4380 setverdict(pass);
4381 }
4382 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4383 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4384 }
4385 [] SGsAP.receive {
4386 setverdict(fail, "Received unexpected message on SGs");
4387 }
4388 }
4389
4390 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4391
4392 /* Wait until the VLR has abort the TMSI reallocation procedure */
4393 f_sleep(45.0);
4394
4395 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4396 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4397
4398 f_sgsap_bssmap_screening();
4399
4400 setverdict(pass);
4401}
4402testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004403 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004404 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004405 f_init(1, true);
4406 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004407
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004408 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004409 vc_conn.done;
4410}
4411
4412private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4413runs on BSC_ConnHdlr {
4414 f_init_handler(pars);
4415 f_sgs_perform_lu();
4416 f_sleep(3.0);
4417
4418 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4419 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4420 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4421 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4422
4423 f_sgsap_bssmap_screening();
4424
4425 setverdict(pass);
4426}
4427testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004428 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004429 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004430 f_init(1, true);
4431 pars := f_init_pars(11814, true);
4432 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004433 vc_conn.done;
4434}
4435
Philipp Maierfc19f172019-03-21 11:17:54 +01004436private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4437runs on BSC_ConnHdlr {
4438 f_init_handler(pars);
4439 f_sgs_perform_lu();
4440 f_sleep(3.0);
4441
4442 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4443 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4444 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4445 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4446
4447 f_sgsap_bssmap_screening();
4448
4449 setverdict(pass);
4450}
4451testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4452 var BSC_ConnHdlrPars pars;
4453 var BSC_ConnHdlr vc_conn;
4454 f_init(1, true);
4455 pars := f_init_pars(11814, true);
4456 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4457 vc_conn.done;
4458}
4459
Harald Welte4263c522018-12-06 11:56:27 +01004460private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4461runs on BSC_ConnHdlr {
4462 f_init_handler(pars);
4463 f_sgs_perform_lu();
4464 f_sleep(3.0);
4465
4466 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4467 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4468 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004469
4470 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4471 setverdict(fail, "subscriber not removed from VLR");
4472 }
Harald Welte4263c522018-12-06 11:56:27 +01004473
4474 f_sgsap_bssmap_screening();
4475
4476 setverdict(pass);
4477}
4478testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004479 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004480 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004481 f_init(1, true);
4482 pars := f_init_pars(11815, true);
4483 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004484 vc_conn.done;
4485}
4486
Philipp Maier5d812702019-03-21 10:51:26 +01004487private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4488runs on BSC_ConnHdlr {
4489 f_init_handler(pars);
4490 f_sgs_perform_lu();
4491 f_sleep(3.0);
4492
4493 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4494 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4495 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4496
4497 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4498 setverdict(fail, "subscriber not removed from VLR");
4499 }
4500
4501 f_sgsap_bssmap_screening();
4502
4503 setverdict(pass);
4504}
4505testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4506 var BSC_ConnHdlrPars pars;
4507 var BSC_ConnHdlr vc_conn;
4508 f_init(1, true);
4509 pars := f_init_pars(11815, true);
4510 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4511 vc_conn.done;
4512}
4513
Harald Welte4263c522018-12-06 11:56:27 +01004514/* Trigger a paging request via VTY and send a paging reject in response */
4515private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4516runs on BSC_ConnHdlr {
4517 f_init_handler(pars);
4518 f_sgs_perform_lu();
4519 f_sleep(1.0);
4520
4521 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4522 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4523 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4524 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4525
4526 /* Initiate paging via VTY */
4527 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4528 alt {
4529 [] SGsAP.receive(exp_resp) {
4530 setverdict(pass);
4531 }
4532 [] SGsAP.receive {
4533 setverdict(fail, "Received unexpected message on SGs");
4534 }
4535 }
4536
4537 /* Now reject the paging */
4538 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4539
4540 /* Wait for the states inside the MSC to settle and check the state
4541 * of the SGs Association */
4542 f_sleep(1.0);
4543 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4544
4545 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4546 * but we also need to cover tha case where the cause code indicates an
4547 * "IMSI detached for EPS services". In those cases the VLR is expected to
4548 * try paging on tha A/Iu interface. This will be another testcase similar to
4549 * this one, but extended with checks for the presence of the A/Iu paging
4550 * messages. */
4551
4552 f_sgsap_bssmap_screening();
4553
4554 setverdict(pass);
4555}
4556testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004557 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004558 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004559 f_init(1, true);
4560 pars := f_init_pars(11816, true);
4561 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004562 vc_conn.done;
4563}
4564
4565/* Trigger a paging request via VTY and send a paging reject that indicates
4566 * that the subscriber intentionally rejected the call. */
4567private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4568runs on BSC_ConnHdlr {
4569 f_init_handler(pars);
4570 f_sgs_perform_lu();
4571 f_sleep(1.0);
4572
4573 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4574 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4575 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4576 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4577
4578 /* Initiate paging via VTY */
4579 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4580 alt {
4581 [] SGsAP.receive(exp_resp) {
4582 setverdict(pass);
4583 }
4584 [] SGsAP.receive {
4585 setverdict(fail, "Received unexpected message on SGs");
4586 }
4587 }
4588
4589 /* Now reject the paging */
4590 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4591
4592 /* Wait for the states inside the MSC to settle and check the state
4593 * of the SGs Association */
4594 f_sleep(1.0);
4595 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4596
4597 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4598 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4599 * to check back how this works and how it can be tested */
4600
4601 f_sgsap_bssmap_screening();
4602
4603 setverdict(pass);
4604}
4605testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004606 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004607 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004608 f_init(1, true);
4609 pars := f_init_pars(11817, true);
4610 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004611 vc_conn.done;
4612}
4613
4614/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4615private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4616runs on BSC_ConnHdlr {
4617 f_init_handler(pars);
4618 f_sgs_perform_lu();
4619 f_sleep(1.0);
4620
4621 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4622 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4623 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4624 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4625
4626 /* Initiate paging via VTY */
4627 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4628 alt {
4629 [] SGsAP.receive(exp_resp) {
4630 setverdict(pass);
4631 }
4632 [] SGsAP.receive {
4633 setverdict(fail, "Received unexpected message on SGs");
4634 }
4635 }
4636
4637 /* Now pretend that the UE is unreachable */
4638 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4639
4640 /* Wait for the states inside the MSC to settle and check the state
4641 * of the SGs Association. */
4642 f_sleep(1.0);
4643 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4644
4645 f_sgsap_bssmap_screening();
4646
4647 setverdict(pass);
4648}
4649testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004650 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004651 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004652 f_init(1, true);
4653 pars := f_init_pars(11818, true);
4654 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004655 vc_conn.done;
4656}
4657
4658/* Trigger a paging request via VTY but don't respond to it */
4659private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4660runs on BSC_ConnHdlr {
4661 f_init_handler(pars);
4662 f_sgs_perform_lu();
4663 f_sleep(1.0);
4664
4665 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4666 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004667 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004668 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4669 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4670
4671 /* Initiate paging via VTY */
4672 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4673 alt {
4674 [] SGsAP.receive(exp_resp) {
4675 setverdict(pass);
4676 }
4677 [] SGsAP.receive {
4678 setverdict(fail, "Received unexpected message on SGs");
4679 }
4680 }
4681
Philipp Maier34218102019-09-24 09:15:49 +02004682 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4683 * after some time */
4684 timer T := 10.0;
4685 T.start
4686 alt {
4687 [] SGsAP.receive(exp_serv_abrt)
4688 {
4689 setverdict(pass);
4690 }
4691 [] SGsAP.receive {
4692 setverdict(fail, "unexpected SGsAP message received");
4693 self.stop;
4694 }
4695 [] T.timeout {
4696 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4697 self.stop;
4698 }
4699 }
4700
4701 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004702 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4703
4704 f_sgsap_bssmap_screening();
4705
4706 setverdict(pass);
4707}
4708testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004709 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004710 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004711 f_init(1, true);
4712 pars := f_init_pars(11819, true);
4713 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004714 vc_conn.done;
4715}
4716
4717/* Trigger a paging request via VTY and slip in an LU */
4718private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4719runs on BSC_ConnHdlr {
4720 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4721 f_init_handler(pars);
4722
4723 /* First we prepar the situation, where the SGs association is in state
4724 * NULL and the confirmed by radio contact indicator is set to false
4725 * as well. This can be archived by performing an SGs LU and then
4726 * resetting the VLR */
4727 f_sgs_perform_lu();
4728 f_sgsap_reset_mme(mp_mme_name);
4729 f_sleep(1.0);
4730 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4731
4732 /* Perform a paging, expect the paging messages on the SGs interface */
4733 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4734 alt {
4735 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4736 setverdict(pass);
4737 }
4738 [] SGsAP.receive {
4739 setverdict(fail, "Received unexpected message on SGs");
4740 }
4741 }
4742
4743 /* Perform the LU as normal */
4744 f_sgs_perform_lu();
4745 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4746
4747 /* Expect a new paging request right after the LU */
4748 alt {
4749 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4750 setverdict(pass);
4751 }
4752 [] SGsAP.receive {
4753 setverdict(fail, "Received unexpected message on SGs");
4754 }
4755 }
4756
4757 /* Test is done now, lets round everything up by rejecting the paging
4758 * cleanly. */
4759 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4760 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4761
4762 f_sgsap_bssmap_screening();
4763
4764 setverdict(pass);
4765}
4766testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004767 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004768 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004769 f_init(1, true);
4770 pars := f_init_pars(11820, true);
4771 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004772 vc_conn.done;
4773}
4774
4775/* Send unexpected unit-data through the SGs interface */
4776private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4777 f_init_handler(pars);
4778 f_sleep(1.0);
4779
4780 /* This simulates what happens when a subscriber without SGs
4781 * association gets unitdata via the SGs interface. */
4782
4783 /* Make sure the subscriber exists and the SGs association
4784 * is in NULL state */
4785 f_perform_lu();
4786 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4787
4788 /* Send some random unit data, the MSC/VLR should send a release
4789 * immediately. */
4790 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4791 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4792
4793 f_sgsap_bssmap_screening();
4794
4795 setverdict(pass);
4796}
4797testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004798 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004799 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004800 f_init(1, true);
4801 pars := f_init_pars(11821, true);
4802 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004803 vc_conn.done;
4804}
4805
4806/* Send unsolicited unit-data through the SGs interface */
4807private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4808 f_init_handler(pars);
4809 f_sleep(1.0);
4810
4811 /* This simulates what happens when the MME attempts to send unitdata
4812 * to a subscriber that is completely unknown to the VLR */
4813
4814 /* Send some random unit data, the MSC/VLR should send a release
4815 * immediately. */
4816 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4817 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4818
4819 f_sgsap_bssmap_screening();
4820
4821 setverdict(pass);
4822}
4823testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004824 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004825 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004826 f_init(1, true);
4827 pars := f_init_pars(11822, true);
4828 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004829 vc_conn.done;
4830}
4831
4832private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4833 /* FIXME: Match an actual payload (second questionmark), the type is
4834 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4835 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4836 setverdict(fail, "Unexpected SMS related PDU from MSC");
4837 mtc.stop;
4838 }
4839}
4840
4841/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4842function f_mt_sms_sgs(inout SmsParameters spars)
4843runs on BSC_ConnHdlr {
4844 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4845 var template (value) RPDU_MS_SGSN rp_mo;
4846 var template (value) PDU_ML3_MS_NW l3_mo;
4847
4848 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4849 var template RPDU_SGSN_MS rp_mt;
4850 var template PDU_ML3_NW_MS l3_mt;
4851
4852 var PDU_ML3_NW_MS sgsap_l3_mt;
4853
4854 var default d := activate(as_other_sms_sgs());
4855
4856 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4857 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09004858 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01004859 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4860
4861 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4862
4863 /* Extract relevant identifiers */
4864 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4865 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4866
4867 /* send CP-ACK for CP-DATA just received */
4868 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4869
4870 SGsAP.send(l3_mo);
4871
4872 /* send RP-ACK for RP-DATA */
4873 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4874 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4875
4876 SGsAP.send(l3_mo);
4877
4878 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4879 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4880
4881 SGsAP.receive(l3_mt);
4882
4883 deactivate(d);
4884
4885 setverdict(pass);
4886}
4887
4888/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4889function f_mo_sms_sgs(inout SmsParameters spars)
4890runs on BSC_ConnHdlr {
4891 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4892 var template (value) RPDU_MS_SGSN rp_mo;
4893 var template (value) PDU_ML3_MS_NW l3_mo;
4894
4895 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4896 var template RPDU_SGSN_MS rp_mt;
4897 var template PDU_ML3_NW_MS l3_mt;
4898
4899 var default d := activate(as_other_sms_sgs());
4900
4901 /* just in case this is routed to SMPP.. */
4902 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4903
4904 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4905 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09004906 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01004907 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4908
4909 SGsAP.send(l3_mo);
4910
4911 /* receive CP-ACK for CP-DATA above */
4912 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4913
4914 if (ispresent(spars.exp_rp_err)) {
4915 /* expect an RP-ERROR message from MSC with given cause */
4916 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4917 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4918 SGsAP.receive(l3_mt);
4919 /* send CP-ACK for CP-DATA just received */
4920 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4921 SGsAP.send(l3_mo);
4922 } else {
4923 /* expect RP-ACK for RP-DATA */
4924 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4925 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4926 SGsAP.receive(l3_mt);
4927 /* send CP-ACO for CP-DATA just received */
4928 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4929 SGsAP.send(l3_mo);
4930 }
4931
4932 deactivate(d);
4933
4934 setverdict(pass);
4935}
4936
4937private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4938runs on BSC_ConnHdlr {
4939 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4940}
4941
4942/* Send a MT SMS via SGs interface */
4943private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4944 f_init_handler(pars);
4945 f_sgs_perform_lu();
4946 f_sleep(1.0);
4947 var SmsParameters spars := valueof(t_SmsPars);
4948 spars.tp.ud := 'C8329BFD064D9B53'O;
4949
4950 /* Trigger SMS via VTY */
4951 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4952 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4953
4954 /* Expect a paging request and respond accordingly with a service request */
4955 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4956 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4957
4958 /* Connection is now live, receive the MT-SMS */
4959 f_mt_sms_sgs(spars);
4960
4961 /* Expect a concluding release from the MSC */
4962 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4963
4964 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4965 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4966
4967 f_sgsap_bssmap_screening();
4968
4969 setverdict(pass);
4970}
4971testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004972 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004973 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004974 f_init(1, true);
4975 pars := f_init_pars(11823, true);
4976 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004977 vc_conn.done;
4978}
4979
4980/* Send a MO SMS via SGs interface */
4981private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4982 f_init_handler(pars);
4983 f_sgs_perform_lu();
4984 f_sleep(1.0);
4985 var SmsParameters spars := valueof(t_SmsPars);
4986 spars.tp.ud := 'C8329BFD064D9B53'O;
4987
4988 /* Send the MO-SMS */
4989 f_mo_sms_sgs(spars);
4990
4991 /* Expect a concluding release from the MSC/VLR */
4992 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4993
4994 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4995 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4996
4997 setverdict(pass);
4998
4999 f_sgsap_bssmap_screening()
5000}
5001testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005002 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005003 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005004 f_init(1, true);
5005 pars := f_init_pars(11824, true);
5006 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005007 vc_conn.done;
5008}
5009
5010/* Trigger sending of an MT sms via VTY but never respond to anything */
5011private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5012 f_init_handler(pars, 170.0);
5013 f_sgs_perform_lu();
5014 f_sleep(1.0);
5015
5016 var SmsParameters spars := valueof(t_SmsPars);
5017 spars.tp.ud := 'C8329BFD064D9B53'O;
5018 var integer page_count := 0;
5019 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5020 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5021 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5022 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5023
5024 /* Trigger SMS via VTY */
5025 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5026
Neels Hofmeyr16237742019-03-06 15:34:01 +01005027 /* Expect the MSC/VLR to page exactly once */
5028 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005029
5030 /* Wait some time to make sure the MSC is not delivering any further
5031 * paging messages or anything else that could be unexpected. */
5032 timer T := 20.0;
5033 T.start
5034 alt {
5035 [] SGsAP.receive(exp_pag_req)
5036 {
5037 setverdict(fail, "paging seems not to stop!");
5038 mtc.stop;
5039 }
5040 [] SGsAP.receive {
5041 setverdict(fail, "unexpected SGsAP message received");
5042 self.stop;
5043 }
5044 [] T.timeout {
5045 setverdict(pass);
5046 }
5047 }
5048
5049 /* Even on a failed paging the SGs Association should stay intact */
5050 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5051
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005052 /* Make sure that the SMS we just inserted is cleared and the
5053 * subscriber is expired. This is necessary because otherwise the MSC
5054 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005055
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005056 f_vty_sms_clear(hex2str(g_pars.imsi));
5057
Harald Welte4263c522018-12-06 11:56:27 +01005058 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5059
5060 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005061
5062 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005063}
5064testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005065 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005066 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005067 f_init(1, true);
5068 pars := f_init_pars(11825, true);
5069 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005070 vc_conn.done;
5071}
5072
5073/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5074private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5075 f_init_handler(pars, 150.0);
5076 f_sgs_perform_lu();
5077 f_sleep(1.0);
5078
5079 var SmsParameters spars := valueof(t_SmsPars);
5080 spars.tp.ud := 'C8329BFD064D9B53'O;
5081 var integer page_count := 0;
5082 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5083 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5084 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5085 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5086
5087 /* Trigger SMS via VTY */
5088 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5089
5090 /* Expect a paging request and reject it immediately */
5091 SGsAP.receive(exp_pag_req);
5092 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5093
5094 /* The MSC/VLR should no longer try to page once the paging has been
5095 * rejected. Wait some time and check if there are no unexpected
5096 * messages on the SGs interface. */
5097 timer T := 20.0;
5098 T.start
5099 alt {
5100 [] SGsAP.receive(exp_pag_req)
5101 {
5102 setverdict(fail, "paging seems not to stop!");
5103 mtc.stop;
5104 }
5105 [] SGsAP.receive {
5106 setverdict(fail, "unexpected SGsAP message received");
5107 self.stop;
5108 }
5109 [] T.timeout {
5110 setverdict(pass);
5111 }
5112 }
5113
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005114 f_vty_sms_clear(hex2str(g_pars.imsi));
5115
Harald Welte4263c522018-12-06 11:56:27 +01005116 /* A rejected paging with IMSI_unknown (see above) should always send
5117 * the SGs association to NULL. */
5118 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5119
5120 f_sgsap_bssmap_screening();
5121
Harald Welte4263c522018-12-06 11:56:27 +01005122 setverdict(pass);
5123}
5124testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005125 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005126 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005127 f_init(1, true);
5128 pars := f_init_pars(11826, true);
5129 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005130 vc_conn.done;
5131}
5132
5133/* Perform an MT CSDB call including LU */
5134private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5135 f_init_handler(pars);
5136
5137 /* Be sure that the BSSMAP reset is done before we begin. */
5138 f_sleep(2.0);
5139
5140 /* Testcase variation: See what happens when we do a regular BSSMAP
5141 * LU first (this should not hurt in any way!) */
5142 if (bssmap_lu) {
5143 f_perform_lu();
5144 }
5145
5146 f_sgs_perform_lu();
5147 f_sleep(1.0);
5148
5149 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5150 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005151
5152 /* Initiate a call via MNCC interface */
5153 f_mt_call_initate(cpars);
5154
5155 /* Expect a paging request and respond accordingly with a service request */
5156 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5157 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5158
5159 /* Complete the call, hold it for some time and then tear it down */
5160 f_mt_call_complete(cpars);
5161 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005162 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005163
5164 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5165 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5166
Harald Welte4263c522018-12-06 11:56:27 +01005167 /* Test for successful return by triggering a paging, when the paging
5168 * request is received via SGs, we can be sure that the MSC/VLR has
5169 * recognized that the UE is now back on 4G */
5170 f_sleep(1.0);
5171 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5172 alt {
5173 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5174 setverdict(pass);
5175 }
5176 [] SGsAP.receive {
5177 setverdict(fail, "Received unexpected message on SGs");
5178 }
5179 }
5180
5181 f_sgsap_bssmap_screening();
5182
5183 setverdict(pass);
5184}
5185
5186/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5187private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5188 f_mt_lu_and_csfb_call(id, pars, true);
5189}
5190testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005191 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005192 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005193 f_init(1, true);
5194 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005195
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005196 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005197 vc_conn.done;
5198}
5199
Harald Welte4263c522018-12-06 11:56:27 +01005200/* Perform a SGSAP LU and then make a CSFB call */
5201private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5202 f_mt_lu_and_csfb_call(id, pars, false);
5203}
5204testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005205 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005206 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005207 f_init(1, true);
5208 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005209
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005210 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005211 vc_conn.done;
5212}
5213
Philipp Maier628c0052019-04-09 17:36:57 +02005214/* Simulate an HLR/VLR failure */
5215private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5216 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5217 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5218
5219 var PDU_SGsAP lur;
5220
5221 f_init_handler(pars);
5222
5223 /* Attempt location update (which is expected to fail) */
5224 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5225 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5226 SGsAP.send(lur);
5227
5228 /* Respond to SGsAP-RESET-INDICATION from VLR */
5229 alt {
5230 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5231 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5232 setverdict(pass);
5233 }
5234 [] SGsAP.receive {
5235 setverdict(fail, "Received unexpected message on SGs");
5236 }
5237 }
5238
5239 f_sleep(1.0);
5240 setverdict(pass);
5241}
5242testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5243 var BSC_ConnHdlrPars pars;
5244 var BSC_ConnHdlr vc_conn;
5245 f_init(1, true, false);
5246 pars := f_init_pars(11811, true, false);
5247 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5248 vc_conn.done;
5249}
5250
Harald Welte4263c522018-12-06 11:56:27 +01005251/* SGs TODO:
5252 * LU attempt for IMSI without NAM_PS in HLR
5253 * LU attempt with AUTH FAIL due to invalid RES/SRES
5254 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5255 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5256 * implicit IMSI detach from EPS
5257 * implicit IMSI detach from non-EPS
5258 * MM INFO
5259 *
5260 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005261
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005262private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5263 f_init_handler(pars);
5264 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005265
5266 f_perform_lu();
5267 f_mo_call_establish(cpars);
5268
5269 f_sleep(1.0);
5270
5271 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5272 var BssmapCause cause := enum2int(cause_val);
5273
5274 var template BSSMAP_FIELD_CellIdentificationList cil;
5275 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5276
5277 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5278 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5279
5280 f_call_hangup(cpars, true);
5281}
5282testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5283 var BSC_ConnHdlr vc_conn;
5284 f_init();
5285
5286 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5287 vc_conn.done;
5288}
5289
5290private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5291 var MgcpCommand mgcp_cmd;
5292 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005293 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005294 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005295 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005296 { int2str(cpars.rtp_payload_type) },
5297 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5298 cpars.rtp_sdp_format)),
5299 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005300 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005301 repeat;
5302 }
5303}
5304
5305private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5306 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005307
5308 f_init_handler(pars);
5309
5310 f_vty_transceive(MSCVTY, "configure terminal");
5311 f_vty_transceive(MSCVTY, "msc");
5312 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5313 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5314 f_vty_transceive(MSCVTY, "exit");
5315 f_vty_transceive(MSCVTY, "exit");
5316
5317 f_perform_lu();
5318 f_mo_call_establish(cpars);
5319
5320 f_sleep(1.0);
5321
5322 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5323
5324 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5325 var BssmapCause cause := enum2int(cause_val);
5326
5327 var template BSSMAP_FIELD_CellIdentificationList cil;
5328 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5329
5330 /* old BSS sends Handover Required */
5331 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5332
5333 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5334
5335 /* MSC forwards the RR Handover Command to old BSS */
5336 var PDU_BSSAP ho_command;
5337 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5338
5339 log("GOT HandoverCommand", ho_command);
5340
5341 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5342
5343 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5344 f_expect_clear();
5345
5346 log("FIRST inter-BSC Handover done");
5347
5348
5349 /* ------------------------ */
5350
5351 /* Ok, that went well, now the other BSC is handovering back here --
5352 * from now on this here is the new BSS. */
5353 f_create_bssmap_exp_handoverRequest(193);
5354
5355 var PDU_BSSAP ho_request;
5356 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5357
5358 /* new BSS composes a RR Handover Command */
5359 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5360 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5361 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5362 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5363 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5364
5365 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5366
5367 f_sleep(0.5);
5368
5369 /* Notify that the MS is now over here */
5370
5371 BSSAP.send(ts_BSSMAP_HandoverDetect);
5372 f_sleep(0.1);
5373 BSSAP.send(ts_BSSMAP_HandoverComplete);
5374
5375 f_sleep(3.0);
5376
5377 deactivate(ack_mdcx);
5378
5379 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5380
5381 /* blatant cheating */
5382 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5383 last_n_sd[0] := 3;
5384 f_bssmap_continue_after_n_sd(last_n_sd);
5385
5386 f_call_hangup(cpars, true);
5387 f_sleep(1.0);
5388 deactivate(ccrel);
5389
5390 setverdict(pass);
5391}
5392private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5393 f_init_handler(pars);
5394 f_create_bssmap_exp_handoverRequest(194);
5395
5396 var PDU_BSSAP ho_request;
5397 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5398
5399 /* new BSS composes a RR Handover Command */
5400 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5401 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5402 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5403 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5404 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5405
5406 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5407
5408 f_sleep(0.5);
5409
5410 /* Notify that the MS is now over here */
5411
5412 BSSAP.send(ts_BSSMAP_HandoverDetect);
5413 f_sleep(0.1);
5414 BSSAP.send(ts_BSSMAP_HandoverComplete);
5415
5416 f_sleep(3.0);
5417
5418 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5419 * ... handover back to the first BSC :P */
5420
5421 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5422 var BssmapCause cause := enum2int(cause_val);
5423
5424 var template BSSMAP_FIELD_CellIdentificationList cil;
5425 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5426
5427 /* old BSS sends Handover Required */
5428 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5429
5430 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5431
5432 /* MSC forwards the RR Handover Command to old BSS */
5433 var PDU_BSSAP ho_command;
5434 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5435
5436 log("GOT HandoverCommand", ho_command);
5437
5438 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5439
5440 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5441 f_expect_clear();
5442 setverdict(pass);
5443}
5444testcase TC_ho_inter_bsc() runs on MTC_CT {
5445 var BSC_ConnHdlr vc_conn0;
5446 var BSC_ConnHdlr vc_conn1;
5447 f_init(2);
5448
5449 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
5450 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
5451
5452 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5453 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5454 vc_conn0.done;
5455 vc_conn1.done;
5456}
5457
5458function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5459 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5460 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5461 log("MS_NW patched enc_l3: ", enc_l3);
5462}
5463
5464private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5465 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005466 var hexstring ho_number := f_gen_msisdn(99999);
5467
5468 f_init_handler(pars);
5469
5470 f_create_mncc_expect(hex2str(ho_number));
5471
5472 f_vty_transceive(MSCVTY, "configure terminal");
5473 f_vty_transceive(MSCVTY, "msc");
5474 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5475 f_vty_transceive(MSCVTY, "exit");
5476 f_vty_transceive(MSCVTY, "exit");
5477
5478 f_perform_lu();
5479 f_mo_call_establish(cpars);
5480
5481 f_sleep(1.0);
5482
5483 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5484
5485 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5486 var BssmapCause cause := enum2int(cause_val);
5487
5488 var template BSSMAP_FIELD_CellIdentificationList cil;
5489 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5490
5491 /* old BSS sends Handover Required */
5492 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5493
5494 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5495 * This MSC tries to reach the other MSC via GSUP. */
5496
5497 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5498 var GSUP_PDU prep_ho_req;
5499 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5500 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5501
5502 var GSUP_IeValue source_name_ie;
5503 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5504 var octetstring local_msc_name := source_name_ie.source_name;
5505
5506 /* Remote MSC has figured out its BSC and signals success */
5507 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5508 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5509 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5510 aoIPTransportLayer := omit,
5511 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5512 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5513 pars.imsi,
5514 ho_number,
5515 remote_msc_name, local_msc_name,
5516 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5517
5518 /* MSC forwards the RR Handover Command to old BSS */
5519 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5520
5521 /* The MS shows up at remote new BSS */
5522
5523 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5524 pars.imsi, remote_msc_name, local_msc_name,
5525 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5526 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5527 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5528 f_sleep(0.1);
5529
5530 /* Save the MS sequence counters for use on the other connection */
5531 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5532
5533 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5534 pars.imsi, remote_msc_name, local_msc_name,
5535 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5536 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5537
5538 /* The local BSS conn clears, all communication goes via remote MSC now */
5539 f_expect_clear();
5540
5541 /**********************************/
5542 /* Play through some signalling across the inter-MSC link.
5543 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5544
5545 if (false) {
5546 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5547 invoke_id := 5, /* Phone may not start from 0 or 1 */
5548 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5549 ussd_string := "*#100#"
5550 );
5551
5552 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5553 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5554 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5555 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5556 )
5557
5558 /* Compose a new SS/REGISTER message with request */
5559 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5560 tid := 1, /* We just need a single transaction */
5561 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5562 facility := valueof(facility_req)
5563 );
5564 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5565
5566 /* Compose SS/RELEASE_COMPLETE template with expected response */
5567 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5568 tid := 1, /* Response should arrive within the same transaction */
5569 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5570 facility := valueof(facility_rsp)
5571 );
5572
5573 /* Compose expected MSC -> HLR message */
5574 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5575 imsi := g_pars.imsi,
5576 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5577 ss := valueof(facility_req)
5578 );
5579
5580 /* To be used for sending response with correct session ID */
5581 var GSUP_PDU gsup_req_complete;
5582
5583 /* Request own number */
5584 /* From remote MSC instead of BSSAP directly */
5585 /* Patch the correct N_SD value into the message. */
5586 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5587 var RAN_Emulation.ConnectionData cd;
5588 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5589 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5590 pars.imsi, remote_msc_name, local_msc_name,
5591 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5592 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5593 ))
5594 ));
5595
5596 /* Expect GSUP message containing the SS payload */
5597 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5598
5599 /* Compose the response from HLR using received session ID */
5600 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5601 imsi := g_pars.imsi,
5602 sid := gsup_req_complete.ies[1].val.session_id,
5603 state := OSMO_GSUP_SESSION_STATE_END,
5604 ss := valueof(facility_rsp)
5605 );
5606
5607 /* Finally, HLR terminates the session */
5608 GSUP.send(gsup_rsp);
5609
5610 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5611 var GSUP_PDU gsup_ussd_rsp;
5612 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5613 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5614
5615 var GSUP_IeValue an_apdu;
5616 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5617 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5618 mtc.stop;
5619 }
5620 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5621 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5622 log("Expecting", ussd_rsp);
5623 log("Got", dtap_mt);
5624 if (not match(dtap_mt, ussd_rsp)) {
5625 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5626 mtc.stop;
5627 }
5628 }
5629 /**********************************/
5630
5631
5632 /* inter-MSC handover back to the first MSC */
5633 f_create_bssmap_exp_handoverRequest(193);
5634 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5635
5636 /* old BSS sends Handover Required, via inter-MSC E link: like
5637 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5638 * but via GSUP */
5639 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5640 pars.imsi, remote_msc_name, local_msc_name,
5641 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5642 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5643 ))
5644 ));
5645
5646 /* MSC asks local BSS to prepare Handover to it */
5647 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5648
5649 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5650 f_bssmap_continue_after_n_sd(last_n_sd);
5651
5652 /* new BSS composes a RR Handover Command */
5653 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5654 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5655 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5656 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5657 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5658
5659 /* HandoverCommand goes out via remote MSC-I */
5660 var GSUP_PDU prep_subsq_ho_res;
5661 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5662 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5663
5664 /* MS shows up at the local BSS */
5665 BSSAP.send(ts_BSSMAP_HandoverDetect);
5666 f_sleep(0.1);
5667 BSSAP.send(ts_BSSMAP_HandoverComplete);
5668
5669 /* Handover Succeeded message */
5670 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5671 pars.imsi, destination_name := remote_msc_name));
5672
5673 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5674 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5675 pars.imsi, destination_name := remote_msc_name));
5676
5677 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5678
5679 f_sleep(1.0);
5680 deactivate(ack_mdcx);
5681
5682 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5683 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5684 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5685 MNCC.clear;
5686
5687 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5688 f_call_hangup(cpars, true);
5689 f_sleep(1.0);
5690 deactivate(ccrel);
5691
5692 setverdict(pass);
5693}
5694testcase TC_ho_inter_msc_out() runs on MTC_CT {
5695 var BSC_ConnHdlr vc_conn;
5696 f_init(1);
5697
5698 var BSC_ConnHdlrPars pars := f_init_pars(54);
5699
5700 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5701 vc_conn.done;
5702}
5703
Oliver Smith1d118ff2019-07-03 10:57:35 +02005704private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5705 pars.net.expect_auth := true;
5706 pars.net.expect_imei := true;
5707 f_init_handler(pars);
5708 f_perform_lu();
5709}
5710testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5711 var BSC_ConnHdlr vc_conn;
5712 f_init();
5713 f_vty_config(MSCVTY, "network", "authentication required");
5714 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5715
5716 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5717 vc_conn.done;
5718}
5719
5720private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5721 pars.net.expect_auth := true;
5722 pars.use_umts_aka := true;
5723 pars.net.expect_imei := true;
5724 f_init_handler(pars);
5725 f_perform_lu();
5726}
5727testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5728 var BSC_ConnHdlr vc_conn;
5729 f_init();
5730 f_vty_config(MSCVTY, "network", "authentication required");
5731 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5732
5733 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5734 vc_conn.done;
5735}
5736
5737private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5738 pars.net.expect_imei := true;
5739 f_init_handler(pars);
5740 f_perform_lu();
5741}
5742testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
5743 var BSC_ConnHdlr vc_conn;
5744 f_init();
5745 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5746
5747 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
5748 vc_conn.done;
5749}
5750
5751private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5752 pars.net.expect_tmsi := false;
5753 pars.net.expect_imei := true;
5754 f_init_handler(pars);
5755 f_perform_lu();
5756}
5757testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
5758 var BSC_ConnHdlr vc_conn;
5759 f_init();
5760 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5761 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5762
5763 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
5764 vc_conn.done;
5765}
5766
5767private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5768 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005769
5770 pars.net.expect_auth := true;
5771 pars.net.expect_imei := true;
5772 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5773 f_init_handler(pars);
5774
5775 /* Cannot use f_perform_lu() as we expect a reject */
5776 l3_lu := f_build_lu_imsi(g_pars.imsi)
5777 f_create_gsup_expect(hex2str(g_pars.imsi));
5778 f_bssap_compl_l3(l3_lu);
5779 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5780
5781 f_mm_common();
5782 f_msc_lu_hlr();
5783 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005784 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005785 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005786}
5787testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
5788 var BSC_ConnHdlr vc_conn;
5789 f_init();
5790 f_vty_config(MSCVTY, "network", "authentication required");
5791 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5792
5793 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
5794 vc_conn.done;
5795}
5796
5797private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5798 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005799
5800 pars.net.expect_auth := true;
5801 pars.net.expect_imei := true;
5802 pars.net.check_imei_error := true;
5803 f_init_handler(pars);
5804
5805 /* Cannot use f_perform_lu() as we expect a reject */
5806 l3_lu := f_build_lu_imsi(g_pars.imsi)
5807 f_create_gsup_expect(hex2str(g_pars.imsi));
5808 f_bssap_compl_l3(l3_lu);
5809 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5810
5811 f_mm_common();
5812 f_msc_lu_hlr();
5813 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005814 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005815 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005816}
5817testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
5818 var BSC_ConnHdlr vc_conn;
5819 f_init();
5820 f_vty_config(MSCVTY, "network", "authentication required");
5821 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5822
5823 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
5824 vc_conn.done;
5825}
5826
5827private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5828 pars.net.expect_auth := true;
5829 pars.net.expect_imei_early := true;
5830 f_init_handler(pars);
5831 f_perform_lu();
5832}
5833testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
5834 var BSC_ConnHdlr vc_conn;
5835 f_init();
5836 f_vty_config(MSCVTY, "network", "authentication required");
5837 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5838
5839 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
5840 vc_conn.done;
5841}
5842
5843private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5844 pars.net.expect_auth := true;
5845 pars.use_umts_aka := true;
5846 pars.net.expect_imei_early := true;
5847 f_init_handler(pars);
5848 f_perform_lu();
5849}
5850testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
5851 var BSC_ConnHdlr vc_conn;
5852 f_init();
5853 f_vty_config(MSCVTY, "network", "authentication required");
5854 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5855
5856 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
5857 vc_conn.done;
5858}
5859
5860private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5861 pars.net.expect_imei_early := true;
5862 f_init_handler(pars);
5863 f_perform_lu();
5864}
5865testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
5866 var BSC_ConnHdlr vc_conn;
5867 f_init();
5868 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5869
5870 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
5871 vc_conn.done;
5872}
5873
5874private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5875 pars.net.expect_tmsi := false;
5876 pars.net.expect_imei_early := true;
5877 f_init_handler(pars);
5878 f_perform_lu();
5879}
5880testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
5881 var BSC_ConnHdlr vc_conn;
5882 f_init();
5883 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5884 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5885
5886 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
5887 vc_conn.done;
5888}
5889
5890private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5891 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005892
5893 pars.net.expect_auth := true;
5894 pars.net.expect_imei_early := true;
5895 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5896 f_init_handler(pars);
5897
5898 /* Cannot use f_perform_lu() as we expect a reject */
5899 l3_lu := f_build_lu_imsi(g_pars.imsi)
5900 f_create_gsup_expect(hex2str(g_pars.imsi));
5901 f_bssap_compl_l3(l3_lu);
5902 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5903
5904 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005905 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005906 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005907}
5908testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
5909 var BSC_ConnHdlr vc_conn;
5910 f_init();
5911 f_vty_config(MSCVTY, "network", "authentication required");
5912 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5913
5914 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
5915 vc_conn.done;
5916}
5917
5918private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5919 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005920
5921 pars.net.expect_auth := true;
5922 pars.net.expect_imei_early := true;
5923 pars.net.check_imei_error := true;
5924 f_init_handler(pars);
5925
5926 /* Cannot use f_perform_lu() as we expect a reject */
5927 l3_lu := f_build_lu_imsi(g_pars.imsi)
5928 f_create_gsup_expect(hex2str(g_pars.imsi));
5929 f_bssap_compl_l3(l3_lu);
5930 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5931
5932 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005933 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005934 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005935}
5936testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
5937 var BSC_ConnHdlr vc_conn;
5938 f_init();
5939 f_vty_config(MSCVTY, "network", "authentication required");
5940 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5941
5942 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
5943 vc_conn.done;
5944}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005945
Neels Hofmeyr8df69622019-11-02 19:16:03 +01005946friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5947 f_init_handler(pars);
5948 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5949
5950 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
5951 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
5952 * will cause a use-after-free after that event dispatch. */
5953 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
5954 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
5955 cpars.rtp_sdp_format := "FOO/8000";
5956 cpars.expect_release := true;
5957
5958 f_perform_lu();
5959 f_mo_call_establish(cpars);
5960}
5961testcase TC_invalid_mgcp_crash() runs on MTC_CT {
5962 var BSC_ConnHdlr vc_conn;
5963 f_init();
5964
5965 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
5966 vc_conn.done;
5967}
5968
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01005969friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
5970runs on BSC_ConnHdlr {
5971 pars.tmsi := 'FFFFFFFF'O;
5972 f_init_handler(pars);
5973
5974 f_create_gsup_expect(hex2str(g_pars.imsi));
5975
5976 /* Initiate Location Updating using an unknown TMSI */
5977 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
5978
5979 /* Expect an Identity Request, send response with no identity */
5980 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
5981 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
5982 lengthIndicator := 1,
5983 mobileIdentityV := {
5984 typeOfIdentity := '000'B,
5985 oddEvenInd_identity := {
5986 no_identity := {
5987 oddevenIndicator := '0'B,
5988 fillerDigits := '00000'H
5989 }
5990 }
5991 }
5992 })));
5993
5994 f_expect_lu_reject();
5995 f_expect_clear();
5996}
5997testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
5998 var BSC_ConnHdlr vc_conn;
5999
6000 f_init();
6001
6002 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7);
6003 vc_conn.done;
6004}
6005
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006006/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6007 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6008 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6009friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6010runs on BSC_ConnHdlr {
6011 var charstring imsi := hex2str(pars.imsi);
6012
6013 f_init_handler(pars);
6014
6015 /* Perform location update */
6016 f_perform_lu();
6017
6018 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6019 f_create_gsup_expect(hex2str(g_pars.imsi));
6020
6021 /* Initiate paging procedure from the VTY */
6022 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6023 f_expect_paging();
6024
6025 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6026 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6027
6028 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6029 f_establish_fully(EST_TYPE_PAG_RESP);
6030
6031 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6032 * In this case we do not send anything and just wait for a Clear Command. */
6033 f_expect_clear();
6034}
6035testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6036 var BSC_ConnHdlr vc_conn;
6037
6038 f_init();
6039
6040 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6041 vc_conn.done;
6042}
6043
Harald Weltef6dd64d2017-11-19 12:09:51 +01006044control {
Philipp Maier328d1662018-03-07 10:40:27 +01006045 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006046 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006047 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006048 execute( TC_lu_imsi_reject() );
6049 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006050 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006051 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006052 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006053 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006054 execute( TC_lu_and_mo_call() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006055 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006056 execute( TC_lu_auth_sai_timeout() );
6057 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006058 execute( TC_lu_clear_request() );
6059 execute( TC_lu_disconnect() );
6060 execute( TC_lu_by_imei() );
6061 execute( TC_lu_by_tmsi_noauth_unknown() );
6062 execute( TC_imsi_detach_by_imsi() );
6063 execute( TC_imsi_detach_by_tmsi() );
6064 execute( TC_imsi_detach_by_imei() );
6065 execute( TC_emerg_call_imei_reject() );
6066 execute( TC_emerg_call_imsi() );
6067 execute( TC_cm_serv_req_vgcs_reject() );
6068 execute( TC_cm_serv_req_vbs_reject() );
6069 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006070 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006071 execute( TC_lu_auth_2G_fail() );
6072 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6073 execute( TC_cl3_no_payload() );
6074 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006075 execute( TC_establish_and_nothing() );
6076 execute( TC_mo_setup_and_nothing() );
6077 execute( TC_mo_crcx_ran_timeout() );
6078 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006079 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006080 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01006081 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006082 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006083 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6084 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6085 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006086 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006087 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6088 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006089 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006090 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006091 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006092
6093 execute( TC_lu_and_mt_call() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006094 execute( TC_lu_and_mt_call_already_paging() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006095
Harald Weltef45efeb2018-04-09 18:19:24 +02006096 execute( TC_lu_and_mo_sms() );
6097 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006098 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006099 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006100 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006101 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006102 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006103 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006104
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006105 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006106 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006107 execute( TC_gsup_mt_sms_ack() );
6108 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006109 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006110 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006111 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006112
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006113 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006114 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006115 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006116 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006117 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006118 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006119
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006120 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006121 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006122 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006123 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006124 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006125
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006126 execute( TC_multi_lu_and_mo_ussd() );
6127 execute( TC_multi_lu_and_mt_ussd() );
6128
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006129 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006130 execute( TC_cipher_complete_1_without_cipher() );
6131 execute( TC_cipher_complete_3_without_cipher() );
6132 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006133 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006134
Harald Welte4263c522018-12-06 11:56:27 +01006135 execute( TC_sgsap_reset() );
6136 execute( TC_sgsap_lu() );
6137 execute( TC_sgsap_lu_imsi_reject() );
6138 execute( TC_sgsap_lu_and_nothing() );
6139 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006140 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006141 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006142 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006143 execute( TC_sgsap_paging_rej() );
6144 execute( TC_sgsap_paging_subscr_rej() );
6145 execute( TC_sgsap_paging_ue_unr() );
6146 execute( TC_sgsap_paging_and_nothing() );
6147 execute( TC_sgsap_paging_and_lu() );
6148 execute( TC_sgsap_mt_sms() );
6149 execute( TC_sgsap_mo_sms() );
6150 execute( TC_sgsap_mt_sms_and_nothing() );
6151 execute( TC_sgsap_mt_sms_and_reject() );
6152 execute( TC_sgsap_unexp_ud() );
6153 execute( TC_sgsap_unsol_ud() );
6154 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6155 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006156 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006157
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006158 execute( TC_ho_inter_bsc_unknown_cell() );
6159 execute( TC_ho_inter_bsc() );
6160
6161 execute( TC_ho_inter_msc_out() );
6162
Oliver Smith1d118ff2019-07-03 10:57:35 +02006163 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6164 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6165 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6166 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6167 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6168 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6169 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6170 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6171 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6172 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6173 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6174 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
6175
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006176 /* Run this last: at the time of writing this test crashes the MSC */
6177 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006178 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02006179 if (mp_enable_osmux_test) {
6180 execute( TC_lu_and_mt_call_osmux() );
6181 }
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006182 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006183 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006184 execute( TC_lu_and_expire_while_paging() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006185}
6186
6187
6188}